VDB
BDU%3A2025-12912
BDU%3A2025-12912
PUBLISHED
CVSS 7 HIGH
Уязвимость файлового архиватора 7-Zip, связанная с неверным определением символических ссылок перед доступом к файлу, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 3.0
7
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «РусБИТех-Астра», Павлов Игорь | Astra Linux Special Edition (запись в едином реестре российских программ №369), 7-Zip | |
| 7-Zip | 7-Zip | 24.09 (x64) |
Timeline
- Oct 7, 2025 PoC Published
- Oct 8, 2025 PoC Published
- Oct 10, 2025 PoC Published
- Oct 10, 2025 PoC Published
- Oct 13, 2025 PoC Published
- Oct 13, 2025 PoC Published
- Oct 13, 2025 PoC Published
- Oct 13, 2025 PoC Published
- Oct 14, 2025 PoC Published
- Oct 14, 2025 PoC Published
- Oct 14, 2025 PoC Published
- Oct 14, 2025 PoC Published
References
- https://github.com/pacbypass/CVE-2025-11001 url
- https://www.zerodayinitiative.com/advisories/ZDI-25-950 url
- https://github.com/ip7z/7zip/releases/tag/25.01 url
- https://www.securitylab.ru/news/564476.php url
- https://habr.com/ru/news/956280 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1020SE47 url
- https://wiki.astralinux.ru/astra-linux-se38-bulletin-2026-0126SE38 url
- ZDI-25-950 url