CVE-2025-0411

Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 4 articles

EPSS Score

Source: FIRST.org · 2026-05-24
46.72%
probability
This CVE has a 46.72% probability of being exploited in the next 30 days.
0% Top 97.7th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Exploits & PoC

dhmosfunk/7-Zip-CVE-2025-0411-POC

This repository contains POC scenarios as part of CVE-2025-0411 MotW bypass.

154
cesarbtakeda/7-Zip-CVE-2025-0411-POC

PoC CVE-2025-0411 — cesarbtakeda/7-Zip-CVE-2025-0411-POC

2
iSee857/CVE-2025-0411-PoC

7-Zip Mark-of-the-Web绕过漏洞PoC(CVE-2025-0411)

1
ishwardeepp/CVE-2025-0411-MoTW-PoC

PoC CVE-2025-0411 — ishwardeepp/CVE-2025-0411-MoTW-PoC

1
4 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
82%
EPSS 46.72%
Mentions 4
Last Seen Feb 04, 2025

CNA Information

Analyst Note

CVE-2025-0411 is a very recent 2025 vulnerability with explicit zero-day exploitation reported against Ukraine by BleepingComputer. The article title directly names it as 'exploited in zero-day attacks,' and the timing (CVE published Jan 25, 2025) aligns with active in-the-wild exploitation. No patch date is documented yet, supporting zero-day classification.

Threat Actors 18

Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
FIN7
apt_group Financial crime 🇷🇺 RU
Hacking Team
apt_group 🇮🇹 IT
Infy
apt_group Information theft and espionage 🇮🇷 IR
YoroTrooper
apt_group Information theft and espionage 🇰🇿 KZ
TAG-100
apt_group Information theft and espionage 🇨🇳 CN
[Unnamed group]
apt_group 🇨🇳 CN
Silent Lynx
apt_group Information theft and espionage 🇰🇿 KZ
Bitwise Spider
apt_group Financial gain 🇷🇺 RU
Pat Bear
apt_group 🇸🇾 SY
Operation Red Signature
apt_group Information theft and espionage 🇨🇳 CN
Operation Digital Eye
apt_group Information theft and espionage 🇨🇳 CN
Unnamed Actor
apt_group 🇨🇳 CN
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Operation Shadow Force
apt_group 🇨🇳 CN
Natohub
apt_group 🇪🇸 ES
UAC-0006
apt_group Information theft and espionage 🇷🇺 RU

Triage Info

Decided atMar 05, 2026