← Vulnerability feed

Vulnerability record · CVE-2025-8088 · published 8 August 2025

CVE-2025-8088: WinRAR path traversal lets crafted archives execute code

Rarlab · Winrar

CVE-2025-8088 is a path traversal flaw in the Windows version of WinRAR that allows attackers to execute arbitrary code by crafting malicious archive files. It was exploited in the wild and discovered by ESET researchers, and CISA added it to the Known Exploited Vulnerabilities catalog, so it is a confirmed active threat rather than a theoretical one.

8.4 CVSS 4.0 High CISA KEV since 12 Aug 2025 Known ransomware use EPSS 94% · top 0.2% CWE-35 · CWE-35
8.4CVSS 4.0 base score
94%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
7References
11 Aug 2026Last modified by NVD

Description

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is a confirmed in-the-wild exploited path traversal with arbitrary code execution, KEV listing, ransomware campaign use and near-maximum EPSS probability.

What it is

CVE-2025-8088 is a path traversal flaw in the Windows version of WinRAR that allows attackers to execute arbitrary code by crafting malicious archive files. It was exploited in the wild and discovered by ESET researchers, and CISA added it to the Known Exploited Vulnerabilities catalog, so it is a confirmed active threat rather than a theoretical one.

Impact

An attacker who gets a victim to open a malicious archive can write files outside the intended extraction directory and achieve arbitrary code execution in the context of the user. This gives full compromise of confidentiality, integrity and availability on the affected host.

Attack surface

The vector is local (AV:L) with user interaction required (UI:A) and no privileges required (PR:N), meaning the attacker must deliver a crafted archive and convince the user to open or extract it. No authentication is needed; the archive is the delivery mechanism.

Exploitation

CISA KEV lists it as exploited in the wild since 2025-08-12 with known ransomware campaign use, and EPSS gives a 30-day probability of 0.938 (99.8th percentile). Reference tags include press coverage of active exploitation by multiple groups, confirming real-world attacks.

What to do

  • Update WinRAR to the latest vendor release that fixes the path traversal; check the WinRAR release notes for the patched version.
  • Apply the vendor and CISA required actions, including BOD 22-01 guidance for cloud services, or discontinue use if patching is not possible.
  • Use the documented mitigation of Software Restriction Policies and Image File Execution Options to block exploitation paths where patching is delayed.
  • Restrict or block archive file execution and extraction from untrusted sources such as email attachments and downloads.
  • Audit endpoints for WinRAR and DTSearch installations and prioritize patching on systems exposed to user-supplied archives.

Detection

  • Monitor for archive extraction processes writing files to unexpected paths outside the intended destination, especially startup folders and system directories.
  • Hunt for WinRAR or DTSearch child processes spawning script interpreters, command shells or other unexpected executables after archive handling.
  • Review file creation events in sensitive locations (Startup, Temp, System32) correlated with recent archive opens.
  • Alert on known exploitation indicators from the ESET and Vicarius detection write-ups, including suspicious archive filenames and traversal sequences.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-8088 to the Known Exploited Vulnerabilities catalog on 12 August 2025 as "RARLAB WinRAR Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 2 September 2025.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-8088 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2025-6218WinRAR path traversal in archive file handling leads to code executionWinRAR mishandles file paths inside archive files, allowing a crafted path to traverse out of the intended extraction directory (CWE-22). Because the…KEVEPSS 90%analysed7.8CVE-2023-38831WinRAR ZIP archive spoofing leads to arbitrary code executionWinRAR before 6.23 mishandles ZIP archives that contain a benign file and a folder with the same name, causing the folder's contents to be processed …KEVEPSS 100%analysed7.8CVE-2018-20250WinRAR ACE filename path traversal enables arbitrary file writeWinRAR versions up to and including 5.61 mishandle the filename field in ACE archives processed by UNACEV2.dll, allowing a crafted filename to be tre…KEVEPSS 96%analysed10.0CVE-2008-7144Rarlab winrar vulnerabilityMultiple unspecified vulnerabilities in RARLAB WinRAR before 3.71 have unknown impact and attack vectors related to crafted (1) ACE, (2) ARJ, (3) BZ2…EPSS 2.3%10.0CVE-2004-1254Rarlab winrar vulnerabilityWinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, …EPSS 10%10.0CVE-2004-0234Clearswift mailsweeper memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow…EPSS 10%9.3CVE-2006-3845Rarlab winrar vulnerabilityStack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a …EPSS 7.9%7.8CVE-2023-40477Rarlab winrar vulnerabilityRARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to e…EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2025-8088), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.