Vulnerability Management

Active exploitation of 7-Zip vulnerability reported

Intrusions involving the high-severity 7-Zip vulnerability, tracked as CVE-2025-11001, were noted by NHS England to be underway, Security Affairs reports.

Affected 7-Zip instances could be subjected to arbitrary code execution through a publicly disclosed proof-of-concept exploit, according to an NHS England alert. Initial details provided by Trend Micro's Zero Day Initiative showed that the flaw, which was discovered by GMO Flatt Security's Ryota Shiga using the firm's artificial intelligence-based Takumi auditor, had stemmed from improper symbolic link management within ZIP files.

"Crafted data in a ZIP file can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of a service account," said the ZDI advisory, which emphasized the need for product interaction to leverage the bug.

Moreover, only Windows machines could be affected by potential attacks with the vulnerability, noted security researcher Dominik, who published the PoC. Immediate patching of vulnerable 7-Zip implementations has been recommended.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds