Close Menu

    Subscribe to Updates

    Get the latest tech news from Tallwire.

      What's Hot

      Meta’s $18 Billion Settlement Puts Pressure on TikTok and YouTube

      August 31, 2026

      Meta’s Anthropic Reliance Exposes the AI Industry’s New Competitive Reality

      August 31, 2026

      States Challenge Federal Push to Shield Prediction Markets From Gambling Laws

      August 31, 2026
      Facebook X (Twitter) Instagram
      • Tech
      • AI
      • Get In Touch
      Facebook X (Twitter) LinkedIn
      TallwireTallwire
      • Tech

        Meta’s Anthropic Reliance Exposes the AI Industry’s New Competitive Reality

        August 31, 2026

        Musk Moves To Break Turbine Bottleneck Threatening America’s AI Expansion

        August 31, 2026

        AI Rivalry With China Raises Stakes Over Control of the Next Technological Era

        August 31, 2026

        Tech Giants Warn AI Cyberattacks Could Soon Overwhelm Existing Defenses

        August 30, 2026

        700 OpenAI Agents Coordinated in Unprecedented Hugging Face Security Breach

        August 30, 2026
      • AI

        Meta’s Anthropic Reliance Exposes the AI Industry’s New Competitive Reality

        August 31, 2026

        Musk Moves To Break Turbine Bottleneck Threatening America’s AI Expansion

        August 31, 2026

        Federal Appeals Court Shields Private Possession of AI-Generated Child Sexual Abuse Images

        August 31, 2026

        AI Rivalry With China Raises Stakes Over Control of the Next Technological Era

        August 31, 2026

        OpenAI Cuts Off Cursor After SpaceX Acquisition Deepens Musk-Altman Feud

        August 31, 2026
      • Security

        AI Rivalry With China Raises Stakes Over Control of the Next Technological Era

        August 31, 2026

        Tech Giants Warn AI Cyberattacks Could Soon Overwhelm Existing Defenses

        August 30, 2026

        700 OpenAI Agents Coordinated in Unprecedented Hugging Face Security Breach

        August 30, 2026

        Darth Vader Satire Puts San Diego’s Flock Surveillance Cameras in the Spotlight

        August 29, 2026

        Chinese Bot Network Targets U.S. Data-Center And Energy Debate

        August 29, 2026
      • Health

        Federal Appeals Court Shields Private Possession of AI-Generated Child Sexual Abuse Images

        August 31, 2026

        Smartwatch Research Finds Seniors Can Accurately Sense Mental Decline

        August 29, 2026

        Silicon Valley Parents Push Back Against Classroom Technology and AI

        August 27, 2026

        Moderna’s Cancer Vaccine Breakthrough Revives Hope for Personalized Oncology

        August 25, 2026

        AI Chatbots Expand Access While Raising New Mental Health Concerns

        August 23, 2026
      • Science

        NASA Launches Roman Space Telescope to Probe the Hidden Universe

        August 31, 2026

        Trump Launches Plan for U.S. Space Academy to Build America’s Next Space Workforce

        August 30, 2026

        Smartwatch Research Finds Seniors Can Accurately Sense Mental Decline

        August 29, 2026

        American-Made Space Armor Heads to Orbit on SpaceX Mission

        August 29, 2026

        Washington Deepens Strategic Rare Earth Investment to Counter China

        August 26, 2026
      • Tech

        Meta’s $18 Billion Settlement Puts Pressure on TikTok and YouTube

        August 31, 2026

        Federal Appeals Court Shields Private Possession of AI-Generated Child Sexual Abuse Images

        August 31, 2026

        OpenAI Cuts Off Cursor After SpaceX Acquisition Deepens Musk-Altman Feud

        August 31, 2026

        AI Giants’ Book-Shredding Push Raises Fears Over Cultural Preservation

        August 30, 2026

        Gen Z’s Fading Handwriting Skills Raise New Concerns About Communication

        August 28, 2026
      TallwireTallwire
      Home»Tech»Critical 7-Zip Vulnerability With Public Exploit Requires Manual Update
      Tech

      Critical 7-Zip Vulnerability With Public Exploit Requires Manual Update

      4 Mins Read
      Facebook Twitter Pinterest LinkedIn Tumblr Email
      Critical 7-Zip Vulnerability With Public Exploit Requires Manual Update
      Critical 7-Zip Vulnerability With Public Exploit Requires Manual Update
      Share
      Facebook Twitter LinkedIn Pinterest Email

      A newly discovered zero-day vulnerability in the widely used archive tool 7-Zip (tracked as CVE-2025-11001 and a related flaw CVE-2025-11002) allows attackers to exploit how the software handles symbolic links inside ZIP files to perform directory traversal and remote code execution. According to advisories from the Zero Day Initiative (ZDI), these flaws carry a CVSS base score of 7.0 and were patched in version 25.00, yet many systems remain vulnerable because 7-Zip lacks an automated update mechanism. The National Health Service England (NHS England) confirmed that a proof-of-concept exploit is publicly available and that some attacks exploiting the flaw may already be taking place. The urgent takeaway is that users and administrators must manually install version 25.01 (or newer) of 7-Zip immediately and apply standard security mitigations for archive file processing.

      Sources: Hack Read, Hacker News

      Key Takeaways

      – The vulnerabilities (CVE-2025-11001 and CVE-2025-11002) stem from improper handling of symbolic links in ZIP files by 7-Zip, enabling directory traversal and potentially remote code execution.

      – Though patched in version 25.00 (and superseded by 25.01), the lack of an internal automatic update mechanism means many users remain exposed.

      – A public proof-of-concept exploit is available and the NHS has issued an alert, making timely manual patching and cautious handling of archive files critical.

      In-Depth

      The widely adopted file archiver software 7‑Zip has come under fresh scrutiny due to two high-severity vulnerabilities that threaten both individual users and enterprise environments. Identified as CVE-2025-11001 and CVE-2025-11002, the flaws exploit how 7-Zip handles symbolic links embedded in ZIP archives. Attackers can craft a malicious archive such that when extracted, it traverses outside the intended extraction directory and writes files to unauthorized locations—potentially enabling arbitrary code execution in the context of a service or privileged account. The advisory from the Zero Day Initiative states that “crafted data in a ZIP file can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of a service account.”

      While these bugs were fixed by the 7-Zip developer (version 25.00) in July 2025, public disclosure only occurred in October, meaning many users were vulnerable for months. Compounding the problem, 7-Zip lacks an automatic update mechanism, so installations—especially portable or unmanaged ones—often remain on outdated builds. Security publications note that numerous systems “escape patch management” because of this.

      The reality of exploit risk has now increased: the NHS England alert confirms a public proof-of-concept (PoC) exploit exists and notes potential active exploitation, even though definitive in-the-wild campaign details remain limited. Given 7-Zip’s broad use across Windows desktops and servers—often for compressed files sent via email, network shares or downloads—the attack surface is significant. It takes only minimal user interaction (opening or extracting an archive) to trigger the vulnerability, which further lowers the barrier for attackers.

      For users and organizations, the mitigation strategy is clear: locate all installations of 7-Zip (including unmanaged or portable copies), determine their version (versions prior to 25.00 are susceptible), and manually update to version 25.01 or newer. Until patched, treat any ZIP files from untrusted sources with high caution: scan them with updated antivirus tools, refuse to open them without assurance, and implement archive-file extraction policies. In enterprise settings, leverage deployment tools (e.g., Intune, SCCM) to push the update and ensure logging of archive-extraction activities.

      Despite the conservative CVSS score of 7.0, the combination of widespread use, a publicly available exploit, and a manual-update requirement elevates the operational risk substantially. For administrators juggling numerous endpoints, this vulnerability acts as a timely reminder: even mature tools like 7-Zip require vigilant patching and process oversight. From a conservative, right-leaning cybersecurity perspective, this reinforces the importance of layered defence, zero-trust handling of untrusted files, and swift manual responses when automatic updates are absent. Patch swiftly, restrict risky extraction behaviour, and you’ll shrink the window of exposure before attackers exploit the gap.

      Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
      Previous ArticleCreepy AI Chatbot PSA Sparks Debate On National AI Regulation
      Next Article Critical GeminiJack Zero-Click Vulnerability in Google Gemini Enterprise Exposed Corporate Data

      Related Posts

      Meta’s Anthropic Reliance Exposes the AI Industry’s New Competitive Reality

      August 31, 2026

      Musk Moves To Break Turbine Bottleneck Threatening America’s AI Expansion

      August 31, 2026

      AI Rivalry With China Raises Stakes Over Control of the Next Technological Era

      August 31, 2026

      Tech Giants Warn AI Cyberattacks Could Soon Overwhelm Existing Defenses

      August 30, 2026
      Add A Comment
      Leave A Reply Cancel Reply

      Editors Picks

      Meta’s Anthropic Reliance Exposes the AI Industry’s New Competitive Reality

      August 31, 2026

      Musk Moves To Break Turbine Bottleneck Threatening America’s AI Expansion

      August 31, 2026

      AI Rivalry With China Raises Stakes Over Control of the Next Technological Era

      August 31, 2026

      Tech Giants Warn AI Cyberattacks Could Soon Overwhelm Existing Defenses

      August 30, 2026
      Popular Topics
      Tim Cook UAE Tech SpaceX spotlight Series A trending Tesla Cybertruck Sundar Pichai Satellite Taiwan Tech Software Viral Space starlink Stocks Tesla Samsung Series B Satya Nadella Startup
      Major Tech Companies
      • Apple News
      • Google News
      • Meta News
      • Microsoft News
      • Amazon News
      • Samsung News
      • Nvidia News
      • OpenAI News
      • Tesla News
      • AMD News
      • Anthropic News
      • Elbit News
      AI & Emerging Tech
      • AI Regulation News
      • AI Safety News
      • AI Adoption
      • Quantum Computing News
      • Robotics News
      Key People
      • Sam Altman News
      • Jensen Huang News
      • Elon Musk News
      • Mark Zuckerberg News
      • Sundar Pichai News
      • Tim Cook News
      • Satya Nadella News
      • Mustafa Suleyman News
      Global Tech & Policy
      • Israel Tech News
      • India Tech News
      • Taiwan Tech News
      • UAE Tech News
      Startups & Emerging Tech
      • Series A News
      • Series B News
      • Startup News
      Tallwire
      Facebook X (Twitter) LinkedIn Threads Instagram RSS
      • Tech
      • Entertainment
      • Business
      • Government
      • Academia
      • Transportation
      • Legal
      • Press Kit
      © 2026 Tallwire. Optimized by ARMOUR Digital Marketing Agency.

      Type above and press Enter to search. Press Esc to cancel.