HIGH

CVE-2025-8088

Rarlab Winrar 2025-08-08 CVSS v3.1
CVSS
8.8
KEV

Description

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček
from ESET.

Summary dbcve.org

A path traversal vulnerability in the Windows version of WinRAR allows attackers to embed malicious paths within archive files that, when extracted by a victim, can write files to arbitrary locations on the filesystem and execute arbitrary code.

Mitigation

Update WinRAR to the latest patched version immediately. Avoid opening archive files from untrusted sources, and exercise caution with any archive files received via email or downloaded from the internet.

Weakness (CWE)

CWE-35

EPSS Score

94.05%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE