Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code
The following platforms are known to be affected:
Exploitation of CVE-2025-11001
Active exploitation of CVE-2025-11001 has been observed in the wild.
A security researcher has also publicly released a proof-of-concept (PoC) exploit for CVE-2025-11001. The PoC allows attackers to abuse symbolic-link handling to write files outside of the intended extraction folder, which in some scenarios, can enable arbitrary code execution .
7-Zip have released a new version that addresses the vulnerability CVE-2025-11001.
CVE-2025-11001 - a File Parsing Directory Traversal Remote Code Execution Vulnerability - CVSS v3 score: 7.0
Affected organisations are encouraged to update 7-Zip to version 25.00 or later as soon as possible.
Last edited: 18 November 2025 3:26 pm
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
