# CVE-2025-0411

## Summary

- **CVE ID:** CVE-2025-0411
- **Severity:** HIGH
- **CVSS Score:** 7 (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
- **CWE:** CWE-693
- **Published:** Jan 25, 2025
- **Last Modified:** Feb 26, 2026

## Description

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.

## Affected Products

- 7-Zip — 7-Zip (24.08 (x64))

## References

- [CNA](https://www.zerodayinitiative.com/advisories/ZDI-25-045/)
- [CVE](http://www.openwall.com/lists/oss-security/2025/01/24/6)
- [CVE](https://www.vicarius.io/vsociety/posts/cve-2025-0411-detection-7-zip-vulnerability)
- [CVE](https://www.vicarius.io/vsociety/posts/cve-2025-0411-7-zip-mitigation-vulnerability)
- [CVE](https://security.netapp.com/advisory/ntap-20250207-0005/)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-0411)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 67.07%
- **EPSS Percentile:** 99.2

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Feb 6, 2025
- **Due Date:** Feb 27, 2025

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._