CVE-2025-53816

Description

7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in versions of 7-Zip prior to 25.0.0. Version 25.0.0 contains a fix for the issue.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.136

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2025-53816,CVE-2025-53817 are fixed in 7zip (.exe package) (25.0.0)Windows
Vulnerabilities CVE-2025-53816,CVE-2025-53817 are fixed in 7zip (x64) (.exe package) (25.0.0)Windows
Vulnerabilities CVE-2025-53816,CVE-2025-53817 are affected in 7zip (.exe package) 24.9Windows
Vulnerabilities CVE-2025-53816,CVE-2025-53817 are affected in 7zip (x64) (.exe package) 24.9Windows
Vulnerabilities CVE-2025-53816,CVE-2025-53817 are affected in 7 Zip (MSI) (x64) 24.9Windows
Vulnerabilities CVE-2025-53816,CVE-2025-53817 are affected in 7 Zip (MSI) 24.9Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-3503147 Zip (exe) (25.01)
PATCH-3503157 Zip (exe) (x64) (25.01)
PATCH-3503147 Zip (exe) (25.01)
PATCH-3503157 Zip (exe) (x64) (25.01)
PATCH-3559907 Zip (MSI) (x64) (26.00)
PATCH-3559897 Zip (MSI) (26.00)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234