Junglewise Threat Intelligence

CVE-2025-60835: IZArc path traversal in unrar.dll via Alternate Data Streams

CVE-2025-60835 · Severity: info · CVSS 7.8 · Published 2026-07-22

Executive brief

IZArc is a free file compression utility for Windows. A vulnerability in how the software handles RAR archives allows an attacker to place malicious files in sensitive system folders, such as the Startup folder, if a user opens a specially crafted archive. This could lead to the attacker gaining full control over the user's computer the next time they log in.

Technical details

A path traversal vulnerability (Zip Slip variant) exists in the unrar.dll component of IZArc v4.6 and earlier. The root cause is the improper validation of Alternate Data Streams (ADS) within RAR archives during the extraction process. By tricking a user into extracting a specially crafted RAR file, a local attacker can bypass intended directory restrictions to write files to arbitrary locations, such as the Windows Startup folder. This primitive can be leveraged to achieve arbitrary code execution (ACE) upon the next user login or system reboot.

Affected products

  • Ivan Zahariev IZArc 4.6 and earlier

Timeline

  • 2026-07-22: advisory: CVE-2025-60835 published by NVD/MITRE

References