• News/
  • https://www.bleepingcomputer.com/news/security/winrar-zero-day-flaw-exploited-by-romcom-hackers-in-phishing-attacks/

WinRAR zero-day exploited to plant malware on archive extraction

BleepingComputer
·
Lawrence Abrams
·
Published Aug 8, 2025
·
Updated

A recently fixed WinRAR vulnerability tracked as CVE-2025-8088 was exploited as a zero-day in phishing attacks to install the RomCom malware. The flaw is a directory traversal vulnerability that was fixed in WinRAR 7.13, which allows specially crafted archives to extract files into a file path selected by the attacker. "When extracting a file, previous versions of WinRAR, Windows versions of RAR, UnRAR, portable UnRAR source code and UnRAR.dll can be tricked into using a path, defined in a specially crafted archive, instead of user specified path," reads the WinRAR 7.13 changelog. "Unix versions of RAR, UnRAR, portable UnRAR source code and UnRAR library, also as RAR for Android, are not affected." Using this vulnerability, attackers can create archives that extract executables into autorun paths, such as the Windows Startup folder located at: The next time a user logs in, the executable will automatically run, allowing the attacker to achieve remote code execution. As WinRAR does not include an auto-update feature, it is strongly advised that all users manually download and install the latest version from win-rar.com so they are protected from this vulnerability. The flaw was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET, with Strýček telling BleepingComputer that it was actively exploited in phishing attacks to install malware. "ESET has observed spearphishing emails with attachments containing RAR files," Strýček told BleepingComputer. These a...

Read full article

Affected Software

1 affected component
WinRAR WinRAR=7.13
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a zero-day vulnerability in WinRAR that was exploited in phishing attacks to deliver the RomCom malware.

2

What security implications are discussed?

The exploitation of a directory traversal vulnerability allowed attackers to install malware during the extraction of archives.

3

What software version is affected by the exploitation?

WinRAR version 7.13 is affected by the zero-day vulnerability CVE-2025-8088.

4

What type of malware is being installed through this exploit?

The exploit is used to deliver the RomCom malware.

5

How was the WinRAR vulnerability exploited by attackers?

Attackers exploited the vulnerability through phishing attacks that trick users into extracting malicious files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203