PT-2025-32352 · Rarlab+1 · Winrar

·

CVE-2025-8088

·

Published

2025-07-30

·

Updated

2026-07-10

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WinRAR versions prior to 7.13
Description A path traversal vulnerability affects the Windows version of WinRAR, allowing attackers to execute arbitrary code by crafting malicious archive files. The issue stems from improper restriction of directory path names, enabling the extraction process to escape the target directory and write files into restricted system folders, such as the Startup folder. This can lead to the automatic execution of malicious code in the context of the current user. This flaw has been exploited in the wild by various threat actors, including Russian APT groups such as Amaranth-Dragon and Gamaredon, to target government networks, defense contractors, and critical infrastructure in Eastern Europe, NATO countries, and Southeast Asia. In some campaigns, attackers used deceptive lures, such as harmless-looking PDF files, to trick users into opening the malicious archives.
Recommendations Update WinRAR to version 7.13 or newer.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09597
CVE-2025-8088

Affected Products

Winrar