CVE-2025-11002

Published: January 23rd, 2026
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the handling of symbolic links in ZIP files. Crafted data in a ZIP file can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of a service account. Was ZDI-CAN-26743.
HIGH
CVSS v3: 7.8

Status

DocFilters Release Package State Justification Comment
0.0.0.1 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
26.1.1 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
26.1 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
25.4 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
25.3 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
25.2 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
25.1.2 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
25.1.1 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
25.1 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.4 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.4.0 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.3 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.2.1 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.2 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
24.1 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
23.3 7-zip (23.01) Not Affected Code Not Present 23.01 does not match CVE configuration.
23.2.1 7-zip (17.01) Not Affected Protected At Runtime CVE does not included required value ‘lzma’
23.2 7-zip (17.01) Not Affected Protected At Runtime CVE does not included required value ‘lzma’
23.1 7-zip (17.01) Not Affected Protected At Runtime CVE does not included required value ‘lzma’
22.4 7-zip (17.01) Not Affected Protected At Runtime CVE does not included required value ‘lzma’

Severity score breakdown

Attack Complexity
LOW
Attack Vector
LOCAL
Availability Impact
HIGH
Base Score
7.8
Base Severity
HIGH
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
REQUIRED
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Version
3.1

References