Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-0411 PoC — 7-Zip Mark-of-the-Web Bypass Vulnerability

Source
Associated Vulnerability
Title: 7-Zip Mark-of-the-Web Bypass Vulnerability (CVE-2025-0411)
Description:7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.
Description
7-Zip Mark-of-the-Web绕过漏洞PoC(CVE-2025-0411)
Readme
https://blog.csdn.net/xc_214/article/details/145324643?spm=1001.2014.3001.5502

使用MinGW-w64进行cpp编译

x86_64-w64-mingw32-g++ loader.cpp -o loader.exe -s -static

![image](https://github.com/user-attachments/assets/b56b4bfb-8155-4593-a3ea-089365b8fe46)

编译后对exe进行7z压缩 执行两次
由于该漏洞需要用户交互,因此生成后的压缩文件需要手动点击,由于24.09版本之前缺乏MotW机制,因此可利用此问题诱导受害者执行

![image](https://github.com/user-attachments/assets/e7aa4dee-1f37-420a-a423-3efadf3bc7e7)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →