Junglewise Threat Intelligence

CVE-2025-8088: RARLAB WinRAR path traversal

CVE-2025-8088 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-08-12

Technologies: RARLAB WinRAR. Vendors: RARLAB.

Executive brief

A vulnerability in the popular file compression utility WinRAR allows attackers to take control of a computer when a user opens a specially crafted archive file. This flaw has been actively exploited by attackers to run malicious software on target systems. Organizations should ensure WinRAR is updated to version 7.13 or later to prevent unauthorized access and data theft.

Technical details

A path traversal vulnerability (CWE-35) exists in the Windows version of WinRAR. The flaw allows an attacker to craft a malicious archive that, when opened or extracted by a user, can write files to arbitrary locations on the filesystem, leading to remote code execution. The attack requires user interaction (opening the file) but no special privileges. This vulnerability was discovered being used as a zero-day in the wild. A fix is available in WinRAR version 7.13.

Affected products

  • RARLAB WinRAR versions up to (excluding) 7.13

Timeline

  • 2025-08-12: disclosed
  • 2025-08-12: kev added: Added to CISA KEV catalog
  • 2025-08-12: advisory

Related threats