A link following vulnerability exists in the 7-Zip component included in MELSOFT Update Manager SW1DND-UDM-M. This vulnerability could allow a local attacker to tamper with or destroy information by convincing a legitimate user to decompress a specially crafted archive file using the affected product. The vulnerability has a high severity score and could lead to a denial-of-service condition if exploited. [truncated]
CVE-2025-53816 is a memory-corruption flaw in 7-Zip's RAR5 handler. According to the CVE record, versions prior to 25.0.0 can write zeroes outside a heap buffer, which may result in denial of service and other memory-corruption effects. Version 25.0.0 is identified as the fix.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-28T02:16:32.283Z and has not been modified since then. The NVD entry is currently Analyzed. 7-Zip for Windows through version 26.01 is vulnerable to a Mark-of-the-Web bypass via RAR5 alternate data stream name collision, allowing an attacker to defeat SmartScreen/MotW warnings and spoof file content [truncated]
CVE-2025-0411 is a 7-Zip Mark of the Web (MOTW) bypass that CISA added to the Known Exploited Vulnerabilities catalog on 2025-02-06. Because CISA has set a mitigation due date of 2025-02-27, organizations should treat affected 7-Zip deployments as an urgent patch and mitigation priority.
CVE-2023-40481 is a high-severity vulnerability affecting Rockwell Automation AADvance Trusted SIS Workstation, published on September 12, 2024. The vulnerability stems from an out-of-bounds write in 7-Zip's SquashFS (SQFS) file parsing functionality, which can be exploited for remote code execution when a user opens a malicious archive or visits a malicious page. The CVSS 3.1 score of 7.8 reflects high i [truncated]