← Vulnerability feed

Vulnerability record · CVE-2025-6218 · published 21 June 2025

CVE-2025-6218: WinRAR path traversal in archive file handling leads to code execution

Rarlab · Winrar

WinRAR mishandles file paths inside archive files, allowing a crafted path to traverse out of the intended extraction directory (CWE-22). Because the traversal can place attacker-controlled files in locations the process later executes, it escalates from a path bug to remote code execution in the context of the current user. It matters because WinRAR is widely deployed and exploitation requires only that a user open a malicious archive or visit a malicious page.

7.8 CVSS 3.0 High CISA KEV since 9 Dec 2025 EPSS 90% · top 0.2% CWE-22 · Path traversal
7.8CVSS 3.0 base score
90%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with a near-certain EPSS score and public exploit references, and successful exploitation yields code execution as the user.

What it is

WinRAR mishandles file paths inside archive files, allowing a crafted path to traverse out of the intended extraction directory (CWE-22). Because the traversal can place attacker-controlled files in locations the process later executes, it escalates from a path bug to remote code execution in the context of the current user. It matters because WinRAR is widely deployed and exploitation requires only that a user open a malicious archive or visit a malicious page.

Impact

An attacker gains arbitrary code execution with the privileges of the user running WinRAR. That typically means full access to the user's files, credentials and any resources that user can reach.

Attack surface

Reached locally through the archive handling path: the CVSS vector is AV:L/PR:N/UI:R, so no authentication is needed but user interaction is required, consistent with the description that the target must open a malicious file or visit a malicious page.

Exploitation

CISA added it to KEV on 2025-12-09 with a 2025-12-30 remediation due date, and EPSS gives a 30-day probability of 0.90538 (99.795th percentile). Two references are tagged Exploit, indicating public exploit material exists; no ransomware campaign use is recorded.

What to do

  • Update WinRAR to the vendor-fixed release referenced in the RARLAB release notes, then verify the installed version across all endpoints.
  • If patching cannot be completed before the KEV due date, restrict or block opening untrusted archives and consider discontinuing WinRAR on exposed systems per CISA guidance.
  • Enforce least privilege so users do not run WinRAR with administrative rights, limiting the impact of code execution.
  • Block archive attachments and downloads from untrusted sources at mail and web gateways where operationally feasible.

Detection

  • Monitor for WinRAR processes writing files outside expected extraction directories, especially into startup folders, user profile paths or system directories.
  • Alert on WinRAR spawning child processes such as script interpreters or command shells, which is abnormal for normal extraction.
  • Hunt for archive files containing path traversal sequences in entry names, and for archives delivered from external or newly registered domains.
  • Review endpoint telemetry for file creation events where the parent process is WinRAR and the target path differs from the user-selected extraction folder.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-6218 to the Known Exploited Vulnerabilities catalog on 9 December 2025 as "RARLAB WinRAR Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 30 December 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-6218 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.4CVE-2025-8088WinRAR path traversal lets crafted archives execute codeCVE-2025-8088 is a path traversal flaw in the Windows version of WinRAR that allows attackers to execute arbitrary code by crafting malicious archive…KEVEPSS 94%analysed7.8CVE-2023-38831WinRAR ZIP archive spoofing leads to arbitrary code executionWinRAR before 6.23 mishandles ZIP archives that contain a benign file and a folder with the same name, causing the folder's contents to be processed …KEVEPSS 100%analysed7.8CVE-2018-20250WinRAR ACE filename path traversal enables arbitrary file writeWinRAR versions up to and including 5.61 mishandle the filename field in ACE archives processed by UNACEV2.dll, allowing a crafted filename to be tre…KEVEPSS 96%analysed10.0CVE-2008-7144Rarlab winrar vulnerabilityMultiple unspecified vulnerabilities in RARLAB WinRAR before 3.71 have unknown impact and attack vectors related to crafted (1) ACE, (2) ARJ, (3) BZ2…EPSS 2.3%10.0CVE-2004-1254Rarlab winrar vulnerabilityWinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, …EPSS 10%10.0CVE-2004-0234Clearswift mailsweeper memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow…EPSS 10%9.3CVE-2006-3845Rarlab winrar vulnerabilityStack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a …EPSS 7.9%7.8CVE-2023-40477Rarlab winrar vulnerabilityRARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to e…EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2025-6218), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.