Executive brief
7-Zip fails to propagate the Mark-of-the-Web (MotW) attribute to files extracted from a crafted archive. This allows remote attackers to bypass security warnings and execute arbitrary code when a user interacts with a malicious archive.
Affected products
- 7-zip 7-zip up to (excluding) 24.09
- NetApp Active IQ Unified Manager Windows version
Timeline
- 2025-01-24: disclosed: Initial disclosure on oss-security mailing list
- 2025-02-06: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-02-06: advisory: Published on NVD
- 2025-02-07: other: NetApp advisory published