LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-8088: RARLAB WinRAR Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 12, 2025
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Sep 2, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-8088 to its Known Exploited Vulnerabilities catalog on Aug 12, 2025, with a federal patch deadline of Sep 2, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.

CVE-2025-8088 is a path traversal vulnerability in the Windows version of RARLAB WinRAR. An attacker can craft a malicious archive file that, when processed by the application, allows arbitrary code execution. This matters because WinRAR is widely used on Windows systems to open and extract compressed archives received via email, downloads, or file shares; successful abuse can give an attacker a foothold on the endpoint without needing additional privileges beyond the user’s own rights.

Public detail is limited to the CISA summary and the associated CWE. Confirm all version ranges, exact attack preconditions, and patch identifiers against the vendor advisory before taking action.

How it works

The flaw belongs to CWE-35 (Path Traversal). In archive-handling software this class of weakness typically arises when the extraction logic fails to sanitize directory traversal sequences (for example, sequences that resolve outside the intended extraction folder). An attacker prepares a specially crafted archive that embeds such sequences. When a user opens or extracts the archive with the vulnerable WinRAR build, the application can write files to unexpected locations on the filesystem. Those files may include executable content that is later run under the context of the logged-on user, resulting in arbitrary code execution.

No public exploit mechanics, payload formats, or specific file-system targets are supplied in the available facts; treat any concrete exploitation details as unconfirmed until verified against the vendor advisory.

Am I affected? How to find it in your systems

The vulnerability affects the Windows version of RARLAB WinRAR. The software is commonly installed on desktop and laptop endpoints, and occasionally on servers used for bulk archive processing or automated extraction jobs.

How to remediate

Apply the vendor-supplied update for WinRAR as the primary remediation. Follow the exact instructions and version guidance published by RARLAB; CISA directs organizations to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for any cloud-hosted instances, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be deployed, reduce exposure with compensating controls:

If your data may have been exposed

Path-traversal flaws that enable code execution can lead to full endpoint compromise and subsequent data theft or ransomware deployment, although ransomware use of this specific CVE is not documented. If you have reason to believe malicious archives were processed on unpatched systems, treat the hosts as potentially compromised: isolate them, collect forensic images, and hunt for persistence and lateral movement. As a quick external check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information already appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedRARLAB · WinRAR
WeaknessCWE-35
Added to CISA KEVAug 12, 2025
Federal patch deadlineSep 2, 2025
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities