HomeNetappCVE-2025-0411

CVE-2025-0411

HIGH
7.0CVSS
Published: 2025-01-25
Updated: 2025-10-27
AI Analysis

Description

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.

CVSS Metrics

Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
local
Complexity
high
Privileges
none
User Action
required
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-693NVD-CWE-noinfo

Metadata

Primary Vendor
NETAPP
Published
1/25/2025
Last Modified
10/27/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

netapp : active_iq_unified_manager7-zip : 7-zip

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-0411 | HIGH Severity | CVEDatabase.com | CVEDatabase.com