CVE-2025-8088
win.rar GmbH WinRAR
Published 8 Aug 2025 · updated 11 Aug 2026 · Analyzed
8.4 High · CVSS 4.0, eset.com
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 12 Aug 2025, with a remediation deadline of 2 Sept 2025 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.
References
- www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=283&cHash=a64b4a8f662d3639dec8d65f47bc93c5 · Release Notes
- arstechnica.com/security/2025/08/high-severity-winrar-0-day-exploited-for-weeks-by-2-groups/ · Press/Media Coverage
- support.dtsearch.com/faq/dts0245.htm · Third Party Advisory
- www.vicarius.io/vsociety/posts/cve-2025-8088-detect-winrar-zero-day · Third Party Advisory
- www.vicarius.io/vsociety/posts/cve-2025-8088-mitigate-winrar-zero-day-using-srp-and-ifeo · Mitigation, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8088 · US Government Resource
- www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/#the-discovery-of-cve-2025-8088 · Press/Media Coverage