Temporary Advertisements:
Ad
Ad
Ad
7-Zip Mark-of-the-Web Bypass Vulnerability [CVE-2025-0411] - POC
by thermos - Friday January 24, 2025 at 02:05 PM
#1
"This vulnerability (CVSS SCORE 7.0) allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user."

Hidden Content
You must register or login to view this content.
Reply
#2
okey, lets see....
Reply
#3
(Jan 24, 2025, 02:05 PM)thermos Wrote: "This vulnerability (CVSS SCORE 7.0) allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user."

12345667899755675
Reply
#4
thanks thermos for this warm code )
Reply
#5
User interaction is required for this exploit to work.
Thanxx

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#6
This sounds very promising. Especially if think about the watering hole attack
Reply
#7
thanks for the vulnerability w post
Reply
#8
Thank you so much for sharing.
Reply
#9
I want to study the poc code, thanks.
Reply
#10
thanks for posting
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Buying one of the the exploit chains for MS Exchange (proxylogon or proxyshell) nightingal33 0 1,019 Sep 26, 2026, 09:26 AM
Last Post: nightingal33
  Dokan Pro Unauthenticated SQL Injection POC | CVSS 10 Loki 51 7,696 Sep 26, 2026, 07:12 AM
Last Post: ruroot
  new wordpress website takeover vuln (video + poc ) zinzeur 322 35,624 Sep 23, 2026, 06:26 PM
Last Post: qoksitwix
  Google Dorks for finding SQL injection vulnerabilities and other security issues 1yush 82 8,733 Sep 22, 2026, 03:12 PM
Last Post: kaliaur0274
  {SECRET} DATABASE OF EXPLOITS lulagain 470 39,249 Sep 22, 2026, 02:50 PM
Last Post: kaliaur0274

Forum Jump:


 Users browsing this forum: 1 Guest(s)