CVE-2025-11002

Public on 2025-10-10
Modified on 2025-10-10
Description
This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation.
The specific flaw exists within the handling of symbolic links in ZIP files. Crafted data in a ZIP file can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of a service account.

NOTE: depending on 7zip. Mark this version as fixed version.
NOTE: https://github.com/ip7z/7zip/releases/tag/25.00
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-25-950/
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.0
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Graphicsmagick1.3 Extra p7zip Pending Fix
Amazon Linux 2023 p7zip 2025-10-27 ALAS2023-2025-1250 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H