{"cvss":0.0,"datePublished":"2025-02-06","dateUpdated":"2025-02-06","description":"7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.","dueDate":"2025-02-27","id":"CVE-2025-0411","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Unknown","notes":"https://www.7-zip.org/history.txt ; https://nvd.nist.gov/vuln/detail/CVE-2025-0411","product":"7-Zip","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","severity":"HIGH","source":"cisa_known_exploited","title":"7-Zip Mark of the Web Bypass Vulnerability","vendor":"7-Zip"}