Skip to content
CC-4719 - Active Exploitation Reported for CVE-2025-11001 in 7

CC-4719 - Active Exploitation Reported for CVE-2025-11001 in 7

Digital.Nhs.Uk [email protected] (NHS Digital) November 18, 2025

Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code

Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code

The following platforms are known to be affected:

Exploitation of CVE-2025-11001

Active exploitation of CVE-2025-11001 has been observed in the wild.

A security researcher has also publicly released a proof-of-concept (PoC) exploit for CVE-2025-11001. The PoC allows attackers to abuse symbolic-link handling to write files outside of the intended extraction folder, which in some scenarios, can enable arbitrary code execution .

7-Zip have released a new version that addresses the vulnerability CVE-2025-11001.

CVE-2025-11001 - a File Parsing Directory Traversal Remote Code Execution Vulnerability - CVSS v3 score: 7.0

Affected organisations are encouraged to update 7-Zip to version 25.00 or later as soon as possible.

Last edited: 18 November 2025 3:26 pm

Extracted Entities

Attack Types (1)

Tools (1)

Vulnerabilities (1)