Russia-linked attackers found and exploited a high-severity WinRAR vulnerability before the maintainers of the Windows file archiver issued a fix. The bug, tracked as CVE-2025-8088, is a path-traversal flaw that affects the Windows version of the decompression tool. It received an 8.4 CVSS rating and, according to WinRAR, has been patched in the newest version, 7.13, released on July 31. "When extracting a file, previous versions of WinRAR, Windows versions of RAR, UnRAR, portable UnRAR source code and UnRAR.dll can be tricked into using a path, defined in a specially crafted archive, instead of user specified path," according to the security advisory. So if you haven't already: update now, and check for these indicators of compromise because RomCom found and exploited the bug as a zero-day. ESET researchers Anton Cherepanov, Peter Kosinar, and Peter Strycek discovered and reported the vulnerability, and told The Register that the Russia-aligned crew plus at least one other criminal group began abusing the security hole prior to the patch. "Most RomCom-related activity occurred between July 18 and July 21," ESET senior malware researcher Anton Cherepanov told The Register, noting that the team hasn't observed any similar exploitation since then. These RomCom exploits were very targeted attacks against financial, manufacturing, defense, and logistics companies in Europe and Canada, used in spearphishing campaigns disguised as job application documents. "According to ESET telem...
Russia's RomCom among those exploiting a WinRAR 0-day in highly-targeted attacks
The Register
·Jessica Lyons
·Published Aug 11, 2025
·Updated
Affected Software
5 affected components
WinRAR WinRAR=7.13
WinRAR WinRAR
WinRAR RAR
WinRAR UnRAR
WinRAR UnRAR.dll
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a high-severity WinRAR vulnerability (CVE-2025-8088) exploited by Russia-linked attackers.
2
What security implications are discussed in this article?
The article highlights that the exploitation of the WinRAR vulnerability poses significant risks to users, especially in targeted attacks.
3
What specific version of WinRAR is affected by the vulnerability?
The vulnerability affects WinRAR version 7.13.
4
Who is believed to be behind the exploitation of the WinRAR vulnerability?
The attacks are believed to be carried out by Russia-linked threat actors.
5
What type of flaw does the WinRAR vulnerability represent?
The vulnerability is identified as a path-traversal flaw.