HIGH
CVE-2025-8088
CVSS
8.8
KEV
Description
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček
from ESET.
Summary dbcve.org
A path traversal vulnerability in the Windows version of WinRAR allows attackers to embed malicious paths within archive files that, when extracted by a victim, can write files to arbitrary locations on the filesystem and execute arbitrary code.
Mitigation
Update WinRAR to the latest patched version immediately. Avoid opening archive files from untrusted sources, and exercise caution with any archive files received via email or downloaded from the internet.
Weakness (CWE)
CWE-35
EPSS Score
94.05%
Probability of exploitation in next 30 days
99.8th percentile
References
https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=283&cHash=a64b4a8f662d3639dec8d65f47bc93c5
Release Notes
https://arstechnica.com/security/2025/08/high-severity-winrar-0-day-exploited-for-weeks-by-2-groups/
Press/Media Coverage
https://support.dtsearch.com/faq/dts0245.htm
Third Party Advisory
https://www.vicarius.io/vsociety/posts/cve-2025-8088-detect-winrar-zero-day
Third Party Advisory
https://www.vicarius.io/vsociety/posts/cve-2025-8088-mitigate-winrar-zero-day-using-srp-and-ifeo
Mitigation, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8088
US Government Resource
https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/#the-discovery-of-cve-2025-8088
Press/Media Coverage
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.