⚡️🚨 NEW - 7-Zip Vulnerabilities Let Attackers…
⚡️🚨 NEW - 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code Remotely
Two high-severity vulnerabilities have been discovered in the popular open-source file archiver, 7-Zip, which could allow remote attackers to execute arbitrary code.
Identified as CVE-2025-11001 and CVE-2025-11002, the flaws affect all versions of the software prior to the latest release and require immediate patching.
The core of both vulnerabilities lies within the way 7-Zip handles symbolic links embedded in ZIP archives.
When a user with a vulnerable version of 7-Zip attempts to decompress the archive, the flawed process can be manipulated to perform a directory traversal.