CVE-2025-8088

win.rar GmbH WinRAR

Published 8 Aug 2025 · updated 11 Aug 2026 · Analyzed

8.4 High · CVSS 4.0, eset.com

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 12 Aug 2025, with a remediation deadline of 2 Sept 2025 for US federal agencies. It has been used in ransomware campaigns.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

References