PT-2025-32352 · Rarlab+1 · Winrar

Anton Cherepanov

+2

·

Published

2025-07-30

·

Updated

2026-06-21

·

CVE-2025-8088

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WinRAR versions prior to 7.13
Description A path traversal issue in the Windows version of WinRAR allows attackers to execute arbitrary code by crafting malicious archive files. The flaw enables attackers to manipulate file paths during decompression, using NTFS Alternate Data Streams (ADS) to write files outside the intended extraction directory, such as the Windows Startup folder, to achieve persistence. This issue has been exploited in the wild by various state-sponsored groups from Russia and China, as well as financially motivated cybercriminals, targeting government, military, and critical infrastructure sectors in Eastern Europe, NATO countries, and Southeast Asia. The attacks often involve phishing campaigns where victims are tricked into opening malicious RAR archives containing lures like PDF files.
Recommendations Update WinRAR to version 7.13 or later. Restrict the use of third-party decompression tools and enforce strict email security policies to block suspicious attachments. Implement network segmentation and monitor for unusual file decompression activity.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09597
CVE-2025-8088

Affected Products

Winrar