{"cveID":"CVE-2025-0411","vendorProject":"7-Zip","product":"7-Zip","vulnerabilityName":"7-Zip Mark of the Web Bypass Vulnerability","dateAdded":"2025-02-06","shortDescription":"7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2025-02-27","knownRansomwareCampaignUse":"Unknown","notes":"https://www.7-zip.org/history.txt ; https://nvd.nist.gov/vuln/detail/CVE-2025-0411","cwes":["CWE-693"],"year":2025,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2025-0411","technique":"T1553.005","technique_name_at_mapping":"Mark-of-the-Web Bypass","mapping_type":"exploitation_technique","capability_group":"feature_bypass","comments":"Attackers can double-archive malicious payloads with 7-Zip to bypass Windows's Mark-of-the-Web security feature, further allowing the bypassing of Microsoft Defender SmartScreen. This allows attackers to disseminate these payloads via methods like email attachments, which would normally be subject to additional scrutiny by the service's protective measures. This flaw was patched in 7-Zip version 24.09.","references":["https://www.trendmicro.com/en_us/research/25/a/cve-2025-0411-ukrainian-organizations-targeted.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-0411","technique":"T1566.001","technique_name_at_mapping":"Spearphishing Attachment","mapping_type":"exploitation_technique","capability_group":"feature_bypass","comments":"Attackers can double-archive malicious payloads with 7-Zip to bypass Windows's Mark-of-the-Web security feature, further allowing the bypassing of Microsoft Defender SmartScreen. This allows attackers to disseminate these payloads via methods like email attachments, which would normally be subject to additional scrutiny by the service's protective measures. This flaw was patched in 7-Zip version 24.09.","references":["https://www.trendmicro.com/en_us/research/25/a/cve-2025-0411-ukrainian-organizations-targeted.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-0411","technique":"T1588.001","technique_name_at_mapping":"Malware","mapping_type":"primary_impact","capability_group":"feature_bypass","comments":"Attackers can double-archive malicious payloads with 7-Zip to bypass Windows's Mark-of-the-Web security feature, further allowing the bypassing of Microsoft Defender SmartScreen. This allows attackers to disseminate these payloads via methods like email attachments, which would normally be subject to additional scrutiny by the service's protective measures. This flaw was patched in 7-Zip version 24.09.","references":["https://www.trendmicro.com/en_us/research/25/a/cve-2025-0411-ukrainian-organizations-targeted.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1553.005","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Mark-of-the-Web Bypass","name_at_mapping":"Mark-of-the-Web Bypass","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":6,"has_detection_strategy":true},{"id":"T1566.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Spearphishing Attachment","name_at_mapping":"Spearphishing Attachment","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":24,"has_detection_strategy":true},{"id":"T1588.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Malware","name_at_mapping":"Malware","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":1,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}