Close Menu

    Subscribe to Updates

    Get the latest tech news from Tallwire.

      What's Hot

      Major Cybercrime Group Claims Theft Of 1.7 Million CarGurus Corporate Records

      March 1, 2026

      Amazon Overtakes Walmart As America’s Largest Company By Revenue

      March 1, 2026

      Google Cracks Down On Android Apps And Developer Accounts In 2025

      March 1, 2026
      Facebook X (Twitter) Instagram
      • Tech
      • AI
      • Get In Touch
      Facebook X (Twitter) LinkedIn
      TallwireTallwire
      • Tech

        Amazon Overtakes Walmart As America’s Largest Company By Revenue

        March 1, 2026

        Chinese Sellers Peddling Anti-Drone Weapons On TikTok Raise Security Alarms

        March 1, 2026

        Say Goodbye to the Undersea Cable That Made the Global Internet Possible

        March 1, 2026

        Microsoft Copilot Bug Exposed “Confidential” Emails Despite Label

        February 28, 2026

        Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

        February 27, 2026
      • AI

        Study Signals AI Search Shift Threatens Traditional Web Traffic Model

        March 1, 2026

        Amazon’s Security Chief Warns AI Will Flood Data, Expand Cyber Risk

        March 1, 2026

        AI Password Generation Poses Major Security Risk, Experts Warn

        February 28, 2026

        Microsoft Copilot Bug Exposed “Confidential” Emails Despite Label

        February 28, 2026

        AI Productivity Gains Concentrated Among High-Skilled Workers, Study Finds

        February 28, 2026
      • Security

        Major Cybercrime Group Claims Theft Of 1.7 Million CarGurus Corporate Records

        March 1, 2026

        Google Cracks Down On Android Apps And Developer Accounts In 2025

        March 1, 2026

        Massive Exposed Database With Billions of Social Security Numbers Sparks Identity Theft Fears

        March 1, 2026

        Amazon’s Security Chief Warns AI Will Flood Data, Expand Cyber Risk

        March 1, 2026

        Password Managers Share a Hidden Weakness

        March 1, 2026
      • Health

        Social Media Addiction Trial Draws Grieving Parents Seeking Accountability From Tech Platforms

        February 19, 2026

        Portugal’s Parliament OKs Law to Restrict Children’s Social Media Access With Parental Consent

        February 18, 2026

        Parents Paint 108 Names, Demand Snapchat Reform After Deadly Fentanyl Claims

        February 18, 2026

        UK Kids Turning to AI Chatbots and Acting on Advice at Alarming Rates

        February 16, 2026

        Landmark California Trial Sees YouTube Defend Itself, Rejects ‘Social Media’ and Addiction Claims

        February 16, 2026
      • Science

        Astronomers Confirm Discovery Of Galaxy Nearly Entirely Composed Of Dark Matter

        March 1, 2026

        Microsoft Claims 100 Percent Renewable Energy Match Across Global Electricity Use

        February 28, 2026

        Taara Beam Launch Brings 25Gbps Optical Wireless Networks to Cities

        February 27, 2026

        Large Hadron Collider Enters Third Shutdown For Major Upgrade

        February 26, 2026

        Google Phases Out Android’s Built-In Weather App, Replacing It With Search-Based Forecasts

        February 25, 2026
      • Tech

        Sam Altman Says ‘AI Washing’ Is Being Used to Mask Corporate Layoffs

        February 28, 2026

        Zuckerberg Testifies In Landmark Trial Over Alleged Teen Social Media Harms

        February 23, 2026

        Gay Tech Networks Under Spotlight In Silicon Valley Culture Debate

        February 23, 2026

        Google Co-Founder’s Epstein Contacts Reignite Scrutiny of Elite Tech Circles

        February 7, 2026

        Bill Gates Denies “Absolutely Absurd” Claims in Newly Released Epstein Files

        February 6, 2026
      TallwireTallwire
      Home»Tech»Critical 7-Zip Vulnerability With Public Exploit Requires Manual Update
      Tech

      Critical 7-Zip Vulnerability With Public Exploit Requires Manual Update

      4 Mins Read
      Facebook Twitter Pinterest LinkedIn Tumblr Email
      Critical 7-Zip Vulnerability With Public Exploit Requires Manual Update
      Critical 7-Zip Vulnerability With Public Exploit Requires Manual Update
      Share
      Facebook Twitter LinkedIn Pinterest Email

      A newly discovered zero-day vulnerability in the widely used archive tool 7-Zip (tracked as CVE-2025-11001 and a related flaw CVE-2025-11002) allows attackers to exploit how the software handles symbolic links inside ZIP files to perform directory traversal and remote code execution. According to advisories from the Zero Day Initiative (ZDI), these flaws carry a CVSS base score of 7.0 and were patched in version 25.00, yet many systems remain vulnerable because 7-Zip lacks an automated update mechanism. The National Health Service England (NHS England) confirmed that a proof-of-concept exploit is publicly available and that some attacks exploiting the flaw may already be taking place. The urgent takeaway is that users and administrators must manually install version 25.01 (or newer) of 7-Zip immediately and apply standard security mitigations for archive file processing.

      Sources: Hack Read, Hacker News

      Key Takeaways

      – The vulnerabilities (CVE-2025-11001 and CVE-2025-11002) stem from improper handling of symbolic links in ZIP files by 7-Zip, enabling directory traversal and potentially remote code execution.

      – Though patched in version 25.00 (and superseded by 25.01), the lack of an internal automatic update mechanism means many users remain exposed.

      – A public proof-of-concept exploit is available and the NHS has issued an alert, making timely manual patching and cautious handling of archive files critical.

      In-Depth

      The widely adopted file archiver software 7‑Zip has come under fresh scrutiny due to two high-severity vulnerabilities that threaten both individual users and enterprise environments. Identified as CVE-2025-11001 and CVE-2025-11002, the flaws exploit how 7-Zip handles symbolic links embedded in ZIP archives. Attackers can craft a malicious archive such that when extracted, it traverses outside the intended extraction directory and writes files to unauthorized locations—potentially enabling arbitrary code execution in the context of a service or privileged account. The advisory from the Zero Day Initiative states that “crafted data in a ZIP file can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of a service account.”

      While these bugs were fixed by the 7-Zip developer (version 25.00) in July 2025, public disclosure only occurred in October, meaning many users were vulnerable for months. Compounding the problem, 7-Zip lacks an automatic update mechanism, so installations—especially portable or unmanaged ones—often remain on outdated builds. Security publications note that numerous systems “escape patch management” because of this.

      The reality of exploit risk has now increased: the NHS England alert confirms a public proof-of-concept (PoC) exploit exists and notes potential active exploitation, even though definitive in-the-wild campaign details remain limited. Given 7-Zip’s broad use across Windows desktops and servers—often for compressed files sent via email, network shares or downloads—the attack surface is significant. It takes only minimal user interaction (opening or extracting an archive) to trigger the vulnerability, which further lowers the barrier for attackers.

      For users and organizations, the mitigation strategy is clear: locate all installations of 7-Zip (including unmanaged or portable copies), determine their version (versions prior to 25.00 are susceptible), and manually update to version 25.01 or newer. Until patched, treat any ZIP files from untrusted sources with high caution: scan them with updated antivirus tools, refuse to open them without assurance, and implement archive-file extraction policies. In enterprise settings, leverage deployment tools (e.g., Intune, SCCM) to push the update and ensure logging of archive-extraction activities.

      Despite the conservative CVSS score of 7.0, the combination of widespread use, a publicly available exploit, and a manual-update requirement elevates the operational risk substantially. For administrators juggling numerous endpoints, this vulnerability acts as a timely reminder: even mature tools like 7-Zip require vigilant patching and process oversight. From a conservative, right-leaning cybersecurity perspective, this reinforces the importance of layered defence, zero-trust handling of untrusted files, and swift manual responses when automatic updates are absent. Patch swiftly, restrict risky extraction behaviour, and you’ll shrink the window of exposure before attackers exploit the gap.

      Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
      Previous ArticleCreepy AI Chatbot PSA Sparks Debate On National AI Regulation
      Next Article Critical GeminiJack Zero-Click Vulnerability in Google Gemini Enterprise Exposed Corporate Data

      Related Posts

      Amazon Overtakes Walmart As America’s Largest Company By Revenue

      March 1, 2026

      Chinese Sellers Peddling Anti-Drone Weapons On TikTok Raise Security Alarms

      March 1, 2026

      Say Goodbye to the Undersea Cable That Made the Global Internet Possible

      March 1, 2026

      Microsoft Copilot Bug Exposed “Confidential” Emails Despite Label

      February 28, 2026
      Add A Comment
      Leave A Reply Cancel Reply

      Editors Picks

      Amazon Overtakes Walmart As America’s Largest Company By Revenue

      March 1, 2026

      Chinese Sellers Peddling Anti-Drone Weapons On TikTok Raise Security Alarms

      March 1, 2026

      Say Goodbye to the Undersea Cable That Made the Global Internet Possible

      March 1, 2026

      Microsoft Copilot Bug Exposed “Confidential” Emails Despite Label

      February 28, 2026
      Popular Topics
      Sundar Pichai SpaceX trending Ransomware Startup spotlight Taiwan Tech Qualcomm Tesla picks UAE Tech Series A Samsung Quantum computing Tim Cook Series B Robotics Tesla Cybertruck Satya Nadella Sam Altman
      Major Tech Companies
      • Apple News
      • Google News
      • Meta News
      • Microsoft News
      • Amazon News
      • Samsung News
      • Nvidia News
      • OpenAI News
      • Tesla News
      • AMD News
      • Anthropic News
      • Elbit News
      AI & Emerging Tech
      • AI Regulation News
      • AI Safety News
      • AI Adoption
      • Quantum Computing News
      • Robotics News
      Key People
      • Sam Altman News
      • Jensen Huang News
      • Elon Musk News
      • Mark Zuckerberg News
      • Sundar Pichai News
      • Tim Cook News
      • Satya Nadella News
      • Mustafa Suleyman News
      Global Tech & Policy
      • Israel Tech News
      • India Tech News
      • Taiwan Tech News
      • UAE Tech News
      Startups & Emerging Tech
      • Series A News
      • Series B News
      • Startup News
      Tallwire
      Facebook X (Twitter) LinkedIn Threads Instagram RSS
      • Tech
      • Entertainment
      • Business
      • Government
      • Academia
      • Transportation
      • Legal
      • Press Kit
      © 2026 Tallwire. Optimized by ARMOUR Digital Marketing Agency.

      Type above and press Enter to search. Press Esc to cancel.