PT-2025-32352 · Rarlab+1 · Winrar

·

CVE-2025-8088

·

Published

2025-07-30

·

Updated

2026-08-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WinRAR versions prior to 7.13
Description A path traversal vulnerability in the Windows version of WinRAR allows attackers to execute arbitrary code by crafting malicious archive files. By using a specially crafted file path within an archive, the extraction process can be forced to write files outside the intended target directory, including system folders such as the Startup folder. This issue has been exploited in the wild by Russian APT groups, including Amaranth-Dragon and Gamaredon, to target government networks, defense contractors, and critical infrastructure in NATO countries and Southeast Asia. These actors have used the flaw to silently install malware and maintain persistence on victim systems.
Recommendations Update WinRAR to version 7.13 or newer.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09597
CVE-2025-8088
OPENSUSE-SU-2026:11583-1

Affected Products

Winrar