7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.
Conclusion & alert: CVE-2025-0411 is rated Critical Active Threat (82.2/100): CVSS High severity, with high exploitation likelihood (EPSS 46.72%, 98th percentile). Core evidence: CISA KEV confirms active exploitation (added 2025-02-06) affecting 7-Zip / 7-Zip. a weakness (CWE-693) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: 7-Zip Mark of the Web Bypass Vulnerability · CISA KEV detail
: 2025-02-06
: 2025-02-27
: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-16 | 52.41% | 46.72% | -5.68% |
| 2 | 2026-03-09 | 50.94% | 52.41% | +1.46% |
| 3 | 2026-03-02 | — | 50.94% | — |
Full EPSS history (49 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.0 | 3.1 | HIGH |
|
1.0 | 5.9 | [email protected] |
| 7.0 | 3.0 | HIGH |
|
1.0 | 5.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2025-0411 unimportant priority: Debian including 2 source packages (7zip, p7zip), 7 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 7. | https://security-tracker.debian.org/tracker/CVE-2025-0411 |
suse
|
high | CVE-2025-0411 severity important: SUSE including 3 source package names (p7zip, p7zip-doc, p7zip-full), 42 product×package rows across 25 product lines (SLES-LTSS-TERADATA 15 SP2, SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS, … (25 product lines)): Known Not Affected 42. | https://www.suse.com/security/cve/CVE-2025-0411/ |
ubuntu
|
high | CVE-2025-0411 high priority: Ubuntu including 2 source packages (7zip, p7zip), 13 status rows across 8 suites (bionic, focal, jammy, noble, oracular, trusty, upstream, xenial): not-affected 10, released 2, DNE 1. | https://ubuntu.com/security/CVE-2025-0411 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| netapp | active_iq_unified_manager | — | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* |
| 7-zip | 7-zip | < 24.09 | cpe:2.3:a:7-zip:7-zip:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-25-045/ | Third Party Advisory VDB Entry |
| http://www.openwall.com/lists/oss-security/2025/01/24/6 | Mailing List |
| https://security.netapp.com/advisory/ntap-20250207-0005/ | Third Party Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2025-0411-7-zip-mitigation-vulnerability | Mitigation |
| https://www.vicarius.io/vsociety/posts/cve-2025-0411-detection-7-zip-vulnerability | Mitigation |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-0411 | US Government Resource |