Path traversal vulnerability in WinRAR
Summary
| CVE | CVE-2025-8088 |
|---|---|
| State | PUBLISHED |
| Assigner | ESET |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-08-08 12:15:29 UTC |
| Updated | 2026-08-11 04:17:18 UTC |
| Description | A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET. |
Risk And Classification
Primary CVSS: v4.0 8.4 HIGH from [email protected]
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.945510000 probability, percentile 0.998470000 (date 2026-08-27)
CISA KEV: Listed on 2025-08-12; due 2025-09-02; ransomware use Known
Problem Types: CWE-35 | CWE-35 CWE-35 Path traversal
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 8.4 | HIGH | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 8.4 | HIGH | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| 3.1 | [email protected] | Primary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
CVSS v4.0 Breakdown
Attack Vector
LocalAttack Complexity
LowAttack Requirements
NonePrivileges Required
NoneUser Interaction
ActiveConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA Known Exploited Vulnerability
| Vendor | RARLAB |
|---|---|
| Product | WinRAR |
| Name | RARLAB WinRAR Path Traversal Vulnerability |
| Required Action | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
| Notes | https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=283&cHash=a64b4a8f662d3639dec8d65f47bc93c5 ; https://nvd.nist.gov/vuln/detail/CVE-2025-8088 |
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Win.rar GmbH | WinRAR | affected 7.12 custom | Windows |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| arstechnica.com/security/2025/08/high-severity-winrar-0-day-exploited-for-wee... | af854a3a-2127-422b-91ae-364da2661108 | arstechnica.com | Press/Media Coverage |
| www.win-rar.com/singlenewsview.html | [email protected] | www.win-rar.com | Release Notes |
| www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-ex... | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.welivesecurity.com | Press/Media Coverage |
| www.vicarius.io/vsociety/posts/cve-2025-8088-mitigate-winrar-zero-day-using-s... | af854a3a-2127-422b-91ae-364da2661108 | www.vicarius.io | Mitigation, Third Party Advisory |
| www.vicarius.io/vsociety/posts/cve-2025-8088-detect-winrar-zero-day | af854a3a-2127-422b-91ae-364da2661108 | www.vicarius.io | Third Party Advisory |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| support.dtsearch.com/faq/dts0245.htm | af854a3a-2127-422b-91ae-364da2661108 | support.dtsearch.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2025-08-12T00:00:00.000Z | CVE-2025-8088 added to CISA KEV |
There are currently no legacy QID mappings associated with this CVE.