← Back to Vulnerability Reports CVE Intelligence

CVE-2025-8088

RARLAB WinRARHIGH · CVSS 8.8 In the wild In CISA KEV

What is CVE-2025-8088?

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

CVSS8.8 NVD 3.1
SeverityHIGH
Exploitation In the wild In CISA KEV
EPSS12% · P94
Triage statusActive Exploit
ActionPatch immediately
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWECWE-35
NVD published2025-08-08
NVD last modified2025-10-30

CISA Known Exploited Vulnerability

RARLAB WinRAR Path Traversal Vulnerability

Added to KEV2025-08-12
Federal patch deadline2025-09-02
Known ransomware useUnknown

Affected product

RARLAB WinRAR

NVD also lists CPE entries for: Rarlab Winrar, Microsoft Windows, Dtsearch

Remediation Steps

  1. Update WinRAR to the latest patched version
  2. Deploy patches across all user endpoints and servers
  3. Educate users to avoid extracting untrusted RAR archives
  4. Monitor systems for suspicious post-extraction activity and stealer malware indicators
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.

Get Critical CVE Alerts

Subscribe free and hear about actively exploited CVEs like this one first.