Junglewise Threat Intelligence

CVE-2025-6218: RARLAB WinRAR path traversal and remote code execution

CVE-2025-6218 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2025-12-09

Technologies: RARLAB WinRAR. Vendors: RARLAB.

Executive brief

WinRAR is a widely used file compression and archiving utility. A security flaw allows attackers to execute malicious code on a user's computer if the user opens a specially crafted archive file or visits a malicious webpage. This vulnerability has been observed being used in active attacks, potentially leading to full system compromise or data theft in the context of the logged-in user.

Technical details

A directory traversal vulnerability (CWE-22) exists in RARLAB WinRAR due to improper handling of file paths within archive files. By crafting an archive with malicious path sequences, an attacker can cause the application to write files to unintended directories during extraction. Exploitation requires user interaction, such as opening a malicious archive file. Successful exploitation allows for remote code execution in the security context of the current user. This vulnerability is tracked as CVE-2025-6218 and has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. The issue is addressed in WinRAR version 7.12.

Affected products

  • RARLAB WinRAR up to (excluding) 7.12

Timeline

  • 2025-06-20: disclosed: Initial disclosure by Zero Day Initiative
  • 2025-12-09: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-12-09: exploited: Confirmed active exploitation in the wild

Related threats