New 7-Zip high-severity vulnerabilities expose systems to remote attackers — users should update to version 25 ASAP

A folder being squeezed in a vice
(Image credit: Pexels / OpenClipArt)

Two newly disclosed vulnerabilities in 7-Zip could allow attackers to execute arbitrary code by tricking users into opening a malicious ZIP archive. The issues, reported October 7 by Trend Micro’s Zero Day Initiative (ZDI), affect multiple builds of the popular open-source compression tool and were quietly fixed in July.

Tracked as CVE-2025-11001 and CVE-2025-11002, the flaws stem from how 7-Zip parses symbolic links within ZIP files. In essence, a crafted archive can escape its intended extraction directory and write files to other locations on the system. When chained, this can escalate to full code execution under the same privileges as the user, which is enough to compromise a Windows environment. Both vulnerabilities carry a CVSS base score of 7.0.

Latest Videos FromTom's Hardware
Luke James
Contributor

Luke James is a freelance writer and journalist.  Although his background is in legal, he has a personal interest in all things tech, especially hardware and microelectronics, and anything regulatory. 

  • rluker5
    Good to know. Updating my 7zip now.
    Reply
  • nrdwka
    Is only 7-zip is affected or any archiver, like windows built-in?
    Reply
  • Notton
    Oh look, 7-zip had a flaw and it got patched just like Winrar

    https://www.tomshardware.com/tech-industry/cyber-security/newly-discovered-winrar-exploit-linked-to-russian-hacking-group-can-plant-backdoor-malware-zero-day-hack-requires-manual-update-to-fix
    Reply
  • shadow.garret
    Oh hey, they didn't call it RCE this time around
    Reply