7-Zip Mark-of-the-Web Bypass Vulnerability [CVE-2025-0411] - POC
by thermos - Friday January 24, 2025 at 02:05 PM
#1
"This vulnerability (CVSS SCORE 7.0) allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user."

Hidden Content
You must register or login to view this content.

Reply
#2
okey, lets see....
Reply
#3
(01-24-2025, 02:05 PM)thermos Wrote: "This vulnerability (CVSS SCORE 7.0) allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user."

12345667899755675
Reply
#4
thanks thermos for this warm code )
Reply
#5
User interaction is required for this exploit to work.
Thanxx
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Leeching | http://breached26tezcofqla4adzyn22notfqw...an-Appeals if you feel this is incorrect.
Reply
#6
This sounds very promising. Especially if think about the watering hole attack
Reply
#7
thanks for the vulnerability w post
Reply
#8
Thank you so much for sharing.
Reply
#9
I want to study the poc code, thanks.
Reply
#10
thanks for posting
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  AMSI Bypass with Powershell W11 pompompurinn 43 7,896 6 hours ago
Last Post: v3nuzc0d3r2325
  CVE-2025-29927 - POC loganpaul09 26 1,187 08-06-2025, 01:12 PM
Last Post: Fuc0
  Nginx RCE - 2025 - March loganpaul09 5 444 08-04-2025, 01:58 AM
Last Post: CLOBELSECTEAM
  CVE-2025-47812 - Wing FTP Server Remote Code Execution (RCE) thermos 7 367 08-03-2025, 08:21 PM
Last Post: handsomexxxxxy
  !Next.js Middleware Bypass (CVE-2025-29927) Rat1337 16 751 08-03-2025, 11:17 AM
Last Post: icebear223

Forum Jump:


 Users browsing this thread: 1 Guest(s)