Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-0411

Опубликовано: 25 янв. 2025
Источник: ubuntu
Приоритет: high
EPSS Средний
CVSS3: 7

Описание

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.

РелизСтатусПримечание
devel

not-affected

24.09+dfsg-3
esm-apps/jammy

not-affected

windows only
esm-apps/noble

not-affected

windows only
esm-infra/focal

DNE

focal

DNE

jammy

not-affected

windows only
noble

not-affected

windows only
oracular

not-affected

windows only
upstream

released

24.09+dfsg-1

Показывать по

РелизСтатусПримечание
devel

not-affected

esm-apps/bionic

not-affected

windows only
esm-apps/focal

not-affected

windows only
esm-apps/jammy

not-affected

windows only
esm-apps/noble

not-affected

esm-apps/xenial

not-affected

windows only
esm-infra-legacy/trusty

not-affected

windows only
focal

not-affected

windows only
jammy

not-affected

windows only
noble

not-affected

16.02+transitional.1

Показывать по

EPSS

Процентиль: 97%
0.36788
Средний

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
nvd
5 месяцев назад

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.

CVSS3: 7
debian
5 месяцев назад

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows ...

CVSS3: 7
github
5 месяцев назад

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.

CVSS3: 7
fstec
9 месяцев назад

Уязвимость механизма защиты Mark-of-the-Web архиватора 7-Zip позволяющая нарушителю выполнить произвольный код в контексте текущего пользователя

redos
4 месяца назад

Уязвимость 7zip

EPSS

Процентиль: 97%
0.36788
Средний

7 High

CVSS3