{"id":148579,"date":"2025-11-19T16:37:08","date_gmt":"2025-11-19T16:37:08","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/148579\/"},"modified":"2025-11-19T16:37:08","modified_gmt":"2025-11-19T16:37:08","slug":"hackers-actively-exploiting-7-zip-symbolic-link-based-rce-vulnerability-cve-2025-11001","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/148579\/","title":{"rendered":"Hackers Actively Exploiting 7-Zip Symbolic Link\u2013Based RCE Vulnerability (CVE-2025-11001)"},"content":{"rendered":"<p>\ue802Nov 19, 2025\ue804Ravie LakshmananVulnerability \/ Threat Intelligence<\/p>\n<p><a href=\"https:\/\/www.newsbeep.com\/ie\/wp-content\/uploads\/2025\/11\/7-zip-exploit.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/ie\/wp-content\/uploads\/2025\/11\/7-zip-exploit.jpg\" alt=\"\" border=\"0\" data-original-height=\"470\" data-original-width=\"900\"\/><\/a><\/p>\n<p>A recently disclosed security flaw impacting 7-Zip has come under active exploitation in the wild, according to an advisory issued by the U.K. NHS England Digital on Tuesday.<\/p>\n<p>The vulnerability in question is <a href=\"https:\/\/www.zerodayinitiative.com\/advisories\/ZDI-25-949\/\" rel=\"noopener nofollow\" target=\"_blank\">CVE-2025-11001<\/a> (CVSS score: 7.0), which allows remote attackers to execute arbitrary code. It has been addressed in 7-Zip version 25.00 <a href=\"https:\/\/www.7-zip.org\/history.txt\" rel=\"noopener nofollow\" target=\"_blank\">released<\/a> in July 2025.<\/p>\n<p>&#8220;The specific flaw exists within the handling of symbolic links in ZIP files. Crafted data in a ZIP file can cause the process to traverse to unintended directories,&#8221; Trend Micro&#8217;s Zero Day Initiative (ZDI) said in an alert released last month. &#8220;An attacker can leverage this vulnerability to execute code in the context of a service account.&#8221;<\/p>\n<p>Ryota Shiga of GMO Flatt Security Inc., along with the company&#8217;s artificial intelligence (AI)-powered AppSec Auditor <a href=\"https:\/\/flatt.tech\/en\/takumi\" rel=\"noopener nofollow\" target=\"_blank\">Takumi<\/a>, has been credited with discovering and reporting the vulnerability. <\/p>\n<p><a href=\"https:\/\/thehackernews.uk\/zz--inside-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"DFIR Retainer Services\" src=\"https:\/\/www.newsbeep.com\/ie\/wp-content\/uploads\/2025\/11\/zz--inside-d.png\" width=\"729\" height=\"91\"\/><\/a><\/p>\n<p>It&#8217;s worth noting that 7-Zip 25.00 also resolves another flaw, <a href=\"https:\/\/www.zerodayinitiative.com\/advisories\/ZDI-25-950\/\" rel=\"noopener nofollow\" target=\"_blank\">CVE-2025-11002<\/a> (CVSS score: 7.0), that allows for remote code execution by taking advantage of improper handling of symbolic links within ZIP archives, resulting in directory traversal. Both shortcomings were introduced in version 21.02.<\/p>\n<p>&#8220;Active exploitation of CVE-2025-11001 has been observed in the wild,&#8221; NHS England Digital <a href=\"https:\/\/digital.nhs.uk\/cyber-alerts\/2025\/cc-4719\" rel=\"noopener nofollow\" target=\"_blank\">said<\/a>. However, there are currently no details available on how it&#8217;s being weaponized, by whom, and in what context.<\/p>\n<p>Given that there exists proof-of-concept (<a href=\"https:\/\/github.com\/pacbypass\/CVE-2025-11001\" rel=\"noopener nofollow\" target=\"_blank\">PoC<\/a>) exploits, it&#8217;s essential that 7-Zip users move quickly to apply the necessary fixes as soon as possible, if not already, for optimal protection.<\/p>\n<p>&#8220;This vulnerability can only be exploited from the context of an elevated user \/ service account or a machine with developer mode enabled,&#8221; security researcher Dominik (aka pacbypass), who released the PoC, <a href=\"https:\/\/pacbypass.github.io\/2025\/10\/16\/diffing-7zip-for-cve-2025-11001.html\" rel=\"noopener nofollow\" target=\"_blank\">said<\/a> in a post detailing the flaws. &#8220;This vulnerability can only be exploited on Windows.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"\ue802Nov 19, 2025\ue804Ravie LakshmananVulnerability \/ Threat Intelligence A recently disclosed security flaw impacting 7-Zip has come under active&hellip;\n","protected":false},"author":2,"featured_media":148580,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[12824,19498,19491,19490,19492,19493,19494,5703,19495,19496,19500,61,14336,60,19501,19499,19497,80,19502],"class_list":["post-148579","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-computer-security","tag-cyber-attacks","tag-cyber-news","tag-cyber-security-news","tag-cyber-security-news-today","tag-cyber-security-updates","tag-cyber-updates","tag-data-breach","tag-hacker-news","tag-hacking-news","tag-how-to-hack","tag-ie","tag-information-security","tag-ireland","tag-network-security","tag-ransomware-malware","tag-software-vulnerability","tag-technology","tag-the-hacker-news"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/148579","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=148579"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/148579\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/148580"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=148579"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=148579"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=148579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}