7-Zip Directory Traversal Vulnerability Leading to Remote Code Execution

Vulnerability

A directory traversal vulnerability allowing remote code execution has been identified in 7-Zip. This issue arises from the application's handling of symbolic links within ZIP files. Crafted ZIP file data can manipulate the extraction process to access unintended directories. As a result, an attacker could execute arbitrary code, potentially under the context of a service account. Exploitation of this vulnerability requires user interaction and may vary based on the specific implementation.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected system.

Remediation

Users can upgrade to 7-Zip version 25.00 to address this vulnerability.

Added: Jan 23, 2026, 4:49 AM
Updated: Jan 23, 2026, 4:49 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
4.2
remediation
7.7
relevance
2.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.