ZeroHour
Security Affairspublished ()ingested @securityaffairs

A 7-Zip bug allows to bypass the Mark of the Web (MotW) feature

mediumVulnerabilityimportance 35CVE-2025-0411

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-0411
Mark-of-the-Web Bypass in 7-Zip Enables Code Execution via Crafted Archives

CVE-2025-0411 is a protection-mechanism bypass in 7-Zip's handling of archived files: when extracting a crafted archive that carries the Mark-of-the-Web, 7-Zip fails to propagate the MotW flag to the extracted files. Exploitation requires user interaction, as the target must visit a malicious page or open a malicious archive. Because the extracted files lose their MotW designation, Windows skips its usual security prompts on attacker-supplied executables or scripts, allowing arbitrary code execution in the context of the current user. Anyone running affected 7-Zip installations is exposed, including NetApp Active IQ Unified Manager deployments that incorporate 7-Zip. The flaw was exploited as a zero-day — Russian cybercrime groups and SmokeLoader campaigns, notably targeting Ukrainian organizations, abused it — and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-06.

Do: Upgrade 7-Zip to the latest patched release per vendor guidance, and for NetApp Active IQ Unified Manager apply the update specified in NetApp's security advisory; the CISA KEV required action is to apply vendor mitigations or discontinue use. Until patched, treat archives from untrusted sources with caution and verify extracted executables manually, since MotW prompts will not fire on extracted files. Hunt for signs of SmokeLoader-style post-extraction execution in user workstations.

7.067% KEV
  • 7-Zip
  • NetApp Active IQ Unified Manager
masstens of millions of users (7-Zip is among the most widely deployed Windows archive utilities, plus NetApp-bundled deployments)
Full article316 words · extracted from securityaffairs.com · click to collapse

A vulnerability in the 7-Zip file software allows attackers to bypass the Mark of the Web (MotW) Windows security feature.

Attackers can exploit a vulnerability, tracked as CVE-2025-0411, in the free, open-source file archiver software 7-Zip to bypass the Mark of the Web (MotW) Windows security feature.

Mark of the Web (MotW) is a security feature in Microsoft Windows that identifies files downloaded from untrusted sources, such as the internet. It helps mitigate security risks by flagging these files for restricted execution.

Threat actors can trigger the issue to execute arbitrary code on users’ computers when extracting specially crafted malicious files from nested archives or visiting a malicious page.

The flaw exists is related to the handling of archived files. 7-Zip fails to propagate the Mark of the Web when extracting files, allowing attackers to execute arbitrary code in the user’s context.

“This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.” reads the advisory published by ZDI. “The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user.”

Peter Girnus reported the flaw through the Trend Micro Zero Day Initiative.

The vulnerability was addressed with the version 24.09.

“The bug was fixed: 7-Zip File Manager didn’t propagate Zone.Identifier stream for extracted files from nested archives (if there is open archive inside another open archive).” reads the change notes for version 24.09.

The 7-Zip users should install the latest version as soon as possible.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, MotW)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/173310/hacking/7-zip-flaw-bypass-the-mark-of-the-web-motw.html