Mitsubishi Electric MELSOFT Update Manager Multiple 7-Zip Vulnerabilities (CVE-2025-11001, CVE-2025-55188, CVE-2025-53816, CVE-2025-53817)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Mitsubishi Electric have disclosed four vulnerabilities in MELSOFT Update Manager (SW1DND-UDM-M), published by CISA as advisory ICSA-26-181-01. The vulnerabilities reside in the 7-Zip archive-handling component bundled with the product and are triggered when a specially crafted archive file is decompressed. The most severe issue, CVE-2025-11001, is a path traversal weakness with a CVSS v3.1 base score of 8.8, and the set collectively allows a local attacker to tamper with or destroy information, cause a denial-of-service condition, or execute arbitrary code on the affected engineering workstation.
MELSOFT Update Manager is the software that manages installation and updates of Mitsubishi Electric's MELSOFT engineering tools on Windows-based engineering and maintenance workstations. Because the flaws are in the bundled 7-Zip decompression logic, exploitation depends on a user opening or the software processing an attacker-supplied archive; the CVSS vectors reflect a local attack vector with low privileges required and, for three of the four issues, user interaction. There is no remote, unauthenticated attack path, but the archive can be delivered by email, removable media, a compromised update source, or any channel that places a malicious file where the tool will process it.
An engineering workstation is a high-value target in an industrial environment: it holds project files, controller credentials, and the tools used to program and configure Mitsubishi Electric PLCs. Arbitrary code execution or file tampering on such a host can be a stepping stone to manipulating controller logic or disrupting operations. CISA reports no known public exploitation specifically targeting these vulnerabilities at this time, and the affected product is not remotely exploitable, but the presence of a critical-severity code-execution path warrants prompt updating to the fixed release and disciplined handling of untrusted archive files.
Threats and Vulnerabilities
CVE-2025-11001, with a CVSS v3.1 score of 8.8, is a path traversal vulnerability (CWE-22) in the 7-Zip component of MELSOFT Update Manager. When a crafted archive is decompressed, directory-traversal sequences in the archive entries allow files to be written outside the intended extraction directory, and because the vulnerability changes scope (S:C in the CVSS vector) with high confidentiality, integrity, and availability impact, a local attacker with low privileges can leverage it to place executable content in a sensitive location and achieve arbitrary code execution on the engineering workstation. This is the highest-severity item in the advisory and the primary code-execution path.
CVE-2025-55188, with a CVSS v3.1 score of 7.9, is an improper link resolution before file access weakness (CWE-59) in the same 7-Zip component. By embedding a symbolic link in a crafted archive, an attacker can cause the decompression process to write to a file path chosen by the attacker rather than the intended destination, resulting in high integrity and availability impact. Like the path traversal issue, this can be used to overwrite or plant files outside the extraction directory, tampering with or destroying information on the host.
CVE-2025-53816 (a heap-based buffer overflow, CWE-122) and CVE-2025-53817 (a NULL pointer dereference, CWE-476), each with a CVSS v3.1 score of 5.0, are denial-of-service vulnerabilities in the 7-Zip archive parser. Processing a malformed archive can corrupt heap memory or dereference a null pointer, causing the affected component to crash. Both carry a local attack vector, low privileges, and user interaction, with the impact limited to availability of the affected product. All four vulnerabilities are resolved by updating the 7-Zip component in the fixed MELSOFT Update Manager release; Mitsubishi Electric is providing version 1.015R or later.
Client Impact
For organizations that operate Mitsubishi Electric MELSOFT engineering software, these vulnerabilities create risk on the Windows workstations used to develop, maintain, and deploy controller programs. A successful path traversal or symbolic link attack allows an attacker to write attacker-controlled files onto the workstation, up to and including code execution, which could compromise project files, engineering credentials, and the integrity of the programs later downloaded to Mitsubishi Electric PLCs. Even the denial-of-service issues can interrupt update and maintenance workflows at inconvenient moments. Because exploitation requires a local vector and, in most cases, user interaction, the practical risk is highest where engineering staff routinely handle archive files from email, vendors, or removable media.
The compliance consequences are relevant for manufacturing and critical-infrastructure operators aligned with frameworks such as IEC 62443, the CISA Cross-Sector Cybersecurity Performance Goals, and internal secure-engineering standards, which call for timely patching of engineering software, controlled handling of files entering the OT environment, and segmentation of engineering workstations from both corporate networks and controllers. A documented evaluation of exposure and a record of applying the 1.015R update support both regulatory obligations and internal change-management requirements, and reinforce the file-handling controls that reduce the likelihood a crafted archive reaches a vulnerable workstation.
Mitigations
The following actions are recommended to reduce exposure to the vulnerabilities in ICSA-26-181-01:
1. Update MELSOFT Update Manager to version 1.015R or later. This is the primary remediation and resolves all four vulnerabilities by updating the bundled 7-Zip component; obtain the fixed release from the Mitsubishi Electric FA download site and follow the vendor's installation guidance.
2. Restrict the handling of untrusted archives on engineering workstations. Treat archive files from email, external media, and third-party sources as untrusted, scan them before use, and avoid decompressing archives from unknown or unverified origins on hosts that run MELSOFT engineering software.
3. Segment and control access to engineering workstations. Place engineering and maintenance workstations on a dedicated network segment separated from corporate and internet-facing networks by firewalls, and restrict which accounts and removable devices can interact with them.
4. Apply least privilege and endpoint protection. Run MELSOFT tools under standard user accounts rather than administrator where feasible, keep anti-virus and endpoint detection current, and enable application and file-write monitoring so that files written outside expected directories are detected.
5. Monitor engineering workstations and controller connections. Forward workstation process, file, and security logs to a SIEM, and baseline the connections from engineering workstations to Mitsubishi Electric PLCs so that anomalous project downloads or configuration changes can be identified quickly.
Applying the 1.015R update and reinforcing untrusted-file handling on engineering workstations are the priority actions for any affected organization.
1898 & Co. Response
1898 & Co. works alongside manufacturers and industrial operators to reduce the risk that vulnerabilities like those in ICSA-26-181-01 introduce to engineering and operational technology environments. Our security consultants have supported clients in inventorying engineering software such as MELSOFT, validating installed versions against active advisories, and confirming that engineering workstations are segmented from corporate networks and from the controllers they program.
Through managed threat detection and response services, 1898 & Co. helps clients monitor engineering workstations for the behaviors these vulnerabilities enable, including files written outside expected directories during archive extraction, unexpected process execution following the handling of an archive, and anomalous connections from engineering hosts to Mitsubishi Electric controllers. Our analysts develop hunt procedures and detection content tuned to a client's deployed platforms so that exploitation attempts can be identified and contained quickly.
Beyond incident response, 1898 & Co. supports vulnerability management and OT security program development, helping organizations establish the patch governance, file-handling controls, and network segmentation that limit the impact of a compromised engineering workstation. Our team is available to assist clients in assessing their exposure to the MELSOFT Update Manager vulnerabilities and in validating that the 1.015R update has been applied across all affected installations.
Sources
1. CISA ICS Advisory ICSA-26-181-01 — Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M