CVE-2025-8088: RARLAB WinRAR Path Traversal Vulnerability
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strý?ek from ESET.
Other sources
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.
— MITRE
RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8088?
The severity of CVE-2025-8088 is critical due to its potential for arbitrary code execution.
How do I fix CVE-2025-8088?
To fix CVE-2025-8088, update WinRAR to the latest version provided by Rarlab.
Which versions of WinRAR are affected by CVE-2025-8088?
CVE-2025-8088 affects all versions of WinRAR on Windows that are prior to the patch addressing this vulnerability.
What types of attacks can CVE-2025-8088 facilitate?
CVE-2025-8088 can facilitate attacks allowing for the execution of arbitrary code upon opening a malicious archive.
Who discovered CVE-2025-8088?
CVE-2025-8088 was discovered by security researchers Anton Cherepanov, Peter Košinár, and Peter Strýček.