CVE-2025-8088
Path traversal vulnerability in WinRAR
Description
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.
In plain language
AI Act nowCVE-2025-8088 is a Windows WinRAR flaw that lets attackers break out of an archive and run code, and because it’s already being exploited in the wild, most small businesses that use WinRAR should act immediately.
What to do
- Update WinRAR to the latest available version from the vendor right away. 2) If you can’t update immediately, stop using WinRAR on Windows systems that can be reached by email/web downloads until you can patch. 3) Ask your IT person to check whether dtsearch dtsearch is also installed and update it if applicable.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
References
- Update now: 7-Zip fixes RCE flaw exploitable with malicious archivesen-us·BleepingComputer· Patch 7-Zip rce
- Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuseen·The Hacker News· Exploited Gamaredon malware
- Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targetsen-us·SecurityWeek· Exploited Turla malware
- Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacksen·The Hacker News· Advisory Google Turla
- Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliancesen·ESET WeLiveSecurity· Research Gamaredon malware
- 15th June – Threat Intelligence Reporten-us·Check Point Research· Exploited Oracle PeopleSoft ShinyHunters
- Old WinRAR Flaw Still Fuels Attacks on Ukraine in 2026en-us·Daily CyberSecurity (securityonline.info)· Exploited WinRAR SHADOW-EARTH-066
- Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgsen·Dark Reading· Exploited WinRAR Shadow-Earth-066
- WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraineen·The Hacker News· Exploited WinRAR Earth Dahu
- Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraineen·The Hacker News· Exploited WinRAR Gamaredon
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-8088 and every CVE in our database. Create a free account — no credit card required.
Create Free Account