Technical Release Report: Active Exploitation of 7-Zip Vulnerability CVE-2025-11001

Listen to this Post

Featured Image

Introduction

A newly exposed weakness inside one of the world’s most widely used compression tools, 7-Zip, has triggered global concern after security agencies confirmed that attackers are now exploiting it in real environments. The flaw, classified as CVE-2025-11001, centers on how the software processes symbolic links inside ZIP archives. This seemingly simple design issue opens the door for code execution attacks when malicious archives are extracted under the wrong conditions. With public proof-of-concept exploits already circulating, and with millions of users relying on 7-Zip every day, the cybersecurity community is racing to warn organizations before the vulnerability becomes a larger threat.

the Original

Active Exploitation Warning

NHS England issued a formal notice confirming that CVE-2025-11001, rated with a CVSS score of 7.0, is under active exploitation. Attackers are already using malicious ZIP files to trigger the flaw on vulnerable versions of 7-Zip.

Core Technical Weakness

The vulnerability stems from how 7-Zip handles symbolic links embedded inside ZIP archives. When crafted carefully, these symlinks allow an archive to escape its intended extraction folder and place files in unintended system directories.

Path Traversal to Code Execution

By using high-risk symlink manipulation, attackers can overwrite or drop files into sensitive paths. Under the right circumstances, this enables the attacker to execute arbitrary code using the permissions of the service account that processes the archive.

Public Proof-of-Concept Increases Risk

A security researcher published a working PoC that demonstrates exactly how an attacker can exploit the symlink flaw. The PoC shows that escaping target directories is not theoretical but fully achievable.

Researcher Attribution

The vulnerability was discovered and reported by Ryota Shiga at GMO Flatt Security Inc., together with contributors from takumi-san.ai. Their research identified the symlink handling weakness and demonstrated how directory traversal could escalate into code execution.

Fix Released in Latest 7-Zip Version

7-Zip version 25.00, released in July 2025, includes a patch addressing the vulnerability. However, many systems still run older versions, leaving a wide window for exploitation.

Conditions for Exploitation

Researcher Dominik, known as pacbypass, emphasized that the flaw is exploitable only under specific conditions: the target must be running with elevated privileges or must be a machine with developer mode enabled. The attack is also restricted to Windows systems.

Urgent Upgrade Recommendation

Security experts strongly recommend that all users upgrade immediately. With PoC material freely available and active exploitation confirmed, outdated installations face significant risk.

What Undercode Say:

Symbolic Links as an Overlooked Attack Surface

Symbolic-link exploitation has long been a niche but potent technique. The core issue is trust: tools like 7-Zip often assume that extracted ZIP content will stay confined to safe directories. When symlinks betray that assumption, the extraction engine becomes a powerful filesystem manipulation tool in an attacker’s hands. This vulnerability is a classic example of how legacy design practices can echo into modern threat landscapes.

Why CVE-2025-11001 Matters Even With User Interaction Required

Some may dismiss the flaw because it requires user interaction, but that is a dangerous oversimplification. Modern phishing playbooks routinely weaponize ZIP archives. Employees frequently open compressed attachments as part of their workflow, enabling attackers to disguise malicious symlinks behind ordinary-looking archive structures. Once opened under elevated contexts, the vulnerability becomes a straight path to system compromise.

Service Accounts as a Silent Weak Point

What makes the flaw particularly concerning is the context in which code executes. Service accounts often possess broader, less monitored privileges. When a malicious ZIP file abuses symlink traversal, the resulting code execution inherits these permissions. This can lead to registry modifications, file replacements, and even lateral movement depending on the environment.

PoC Availability Accelerates the Threat Lifecycle

When vulnerabilities are discovered, attackers usually require time to reverse-engineer them. In this case, that gap vanished the moment a public PoC dropped. With a ready-made exploit published online, even low-skill threat actors can begin experimenting with malicious ZIP payloads. This democratization of offensive capability is what transforms a medium-risk bug into an actively exploited threat.

The Windows-Only Caveat Still Leaves Millions Exposed

Although the flaw affects only Windows deployments, that still represents a massive portion of 7-Zip’s user base. Windows environments dominate enterprise networks, meaning the majority of production systems rely heavily on ZIP handling for daily operations. Restricting the exploit to elevated or developer-mode contexts narrows the attack surface but does not eliminate it.

Directory Traversal Vulnerabilities Remain Underrated

Despite years of awareness, directory traversal bugs continue to appear in critical tools. The recurring pattern reflects a deeper architectural issue: extraction utilities often prioritize convenience over filesystem safety. Attackers exploit that trust gap. CVE-2025-11001 underscores how essential it is for developers to treat every filesystem operation as potentially unsafe.

Patch Adoption Will Be the Turning Point

The real danger now lies not in the vulnerability itself but in the adoption rate of version 25.00. Many organizations lag in updating compression utilities because they appear low-risk or peripheral. This mentality is what attackers rely on. The sooner enterprises push the updated version across their fleets, the faster the exploitation window closes.

A Wake-Up Call for Secure Archive Handling

This incident should ignite a broader conversation about how software handles file extraction. Symlink validation, directory containment, and privilege-aware processing need to be standard features. Until then, archive-based attacks will continue to find footholds.

Fact Checker Results

✅ CVE-2025-11001 is confirmed as being exploited in the wild.

✅ A public PoC is available and demonstrates the symlink traversal flaw.

❌ The vulnerability is not universal; exploitation conditions limit it to Windows under elevated or developer-mode contexts.

Prediction

In the coming weeks, more attackers will adopt this vulnerability because of the publicly available PoC. Automated malware kits will integrate ZIP symlink payloads, increasing infection attempts. Organizations that delay updating to version 25.00 will likely see targeted attacks focusing on privileged service accounts and automated extraction pipelines.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: securityaffairs.com
Extra Source Hub (Possible Sources for article):
https://www.github.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon