LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-0411: 7-Zip Mark of the Web Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 6, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 27, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-0411 to its Known Exploited Vulnerabilities catalog on Feb 6, 2025, with a federal patch deadline of Feb 27, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.

CVE-2025-0411 is a protection mechanism failure in 7-Zip that lets remote attackers bypass the Mark-of-the-Web security feature. Successful abuse can lead to arbitrary code execution under the privileges of the logged-in user. Because 7-Zip is widely used to open archives received by email or download, the flaw matters to any organization that relies on it for routine file handling; defenders should treat it as a high-priority item until the vendor fix is confirmed and applied.

Public detail is limited to the CISA summary and the CWE classification. Exact affected versions, exploit mechanics, and scoring must be verified against the vendor advisory before any inventory or remediation decisions are finalized.

How it works

The vulnerability is classified as CWE-693 (Protection Mechanism Failure). Mark-of-the-Web is a Windows security attribute that flags files originating from untrusted sources so that applications can apply extra scrutiny or block automatic execution. In this case the protection fails inside 7-Zip, allowing an attacker who can deliver a specially crafted archive to cause the archive contents to be treated as if they lacked the Mark-of-the-Web. Once the bypass occurs, code can run with the rights of the current user. No further exploit details are provided in the available facts; any concrete attack chain must be confirmed from the vendor advisory.

Am I affected? How to find it in your systems

7-Zip is commonly installed on Windows workstations and servers used by help-desk, finance, engineering, and any team that routinely unpacks compressed files. Inventory steps:

Because version ranges are not supplied here, treat every installation as potentially vulnerable until the advisory is consulted.

How to remediate

Apply the vendor-supplied update for 7-Zip as soon as it is available and verified. The CISA-required action is to follow the vendor’s mitigation instructions or to discontinue use of the product if no mitigations exist. After patching:

If you can't patch immediately

Until the official update can be deployed, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to unauthorized code execution and subsequent data access. Known ransomware use is not documented for CVE-2025-0411, yet any successful compromise still warrants investigation. Review endpoint and network logs for indicators of post-exploitation activity, reset credentials of affected users, and consider running a free exposure scan of organizational email addresses against known breach data sets to determine whether credentials or other information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

Affected7-Zip · 7-Zip
WeaknessCWE-693
Added to CISA KEVFeb 6, 2025
Federal patch deadlineFeb 27, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities