Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
7zip-CVE-2025-11001 — Python exploit for CVE-2025-11001 targeting 7-Zip on Windows, leveraging symlink creation to achieve code execution when 7-Zip runs with Admin privileges. | Kitploit
Tools/GitHubGitHub/lastvocher/7zip-cve-2025-11001
Privilege EscalationPayload GenerationVulnerability AnalysisExploitationBinary Exploitation
GitHublastvocher/7zip-cve-2025-11001

7zip-CVE-2025-11001

Python exploit for CVE-2025-11001 targeting 7-Zip on Windows, leveraging symlink creation to achieve code execution when 7-Zip runs with Admin privileges.

View Repository
1210 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Usage:

python3 exploit.py -t "C:\Users\pac\Desktop" -o demo.zip --data-file calc.exe

Exploiting 7-zip

The vulnerability is only exploitable on windows and has one major caveat.The bug can only be exploited when 7-Zip is ran with Admin privileges for this vulnerability to be succesfully exploited. This is because it the 7-zip process creates a symlink, which is a privileged operation on windows.

Hence the exploitation only makes sense when 7-Zip is used by a service account.

You can find more info about the vulnerability in my blog post https://pacbypass.github.io/2025/10/16/diffing-7zip-for-cve-2025-11001.html

Vulnerable versions: 21.02 - 25.00

Download Tool