PT-2025-26225 · Winrar · Winrar

Marcin Bobryk

·

Published

2025-06-19

·

Updated

2026-06-23

·

CVE-2025-6218

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RARLAB WinRAR versions prior to 7.12
Description A directory traversal flaw exists in the handling of file paths within archive files. This issue allows remote attackers to execute arbitrary code in the context of the current user if a target opens a specially crafted malicious file or visits a malicious page. The flaw enables the extraction process to traverse to unintended directories, including sensitive system folders such as Startup, which can lead to the automatic execution of malicious code. This issue has been actively exploited in the wild by threat groups including APT-C-08 (Manlinghua), GOFFEE, and Bitter, and has been used in campaigns to deploy QuasarRAT malware.
Recommendations Update to version 7.12 or later.

Exploit

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07480
CVE-2025-6218
ZDI-25-409

Affected Products

Winrar