Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5022 articles · 188920 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2025-8088KEVEXPLOITEDPATCHED
rarlab · winrar

Path traversal vulnerability in WinRAR

Description

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

Affected Products

VendorProductVersions
rarlabwinrar0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
dtsearchdtsearchcve_cpe95%
microsoftwindowscve_cpe95%

References

  • https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=283&cHash=a64b4a8f662d3639dec8d65f47bc93c5

Related News (8 articles)

Tier D
Heise Security1d ago
Sicherheitslücken: Angreifer können Wachdienst von ClamAV stören
→ No new info (linked only)
Tier B
CERT-FR2d ago
Multiples vulnérabilités dans ClamAV (10 août 2026)
→ No new info (linked only)
Tier D
BleepingComputer24d ago
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
→ No new info (linked only)
Tier D
The Hacker News44d ago
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
→ No new info (linked only)
Tier D
Dark Reading64d ago
Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs
→ No new info (linked only)
Tier D
The Hacker News64d ago
WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
→ No new info (linked only)
Tier D
The Hacker News70d ago
Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
→ No new info (linked only)
Tier D
Infosecurity Magazine72d ago
FSB Group Gamaredon Hides Worm in Windows Data Streams
→ No new info (linked only)
CVSS 3.18.8 NONE
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
7.132023.01
CWECWE-35
PublishedAug 8, 2025
Last enriched44d agov6
Tags
malwaredata theftcyber attackUkrainecyberespionageAPTspear-phishing
Trending Score113🔥
Source articles8
Independent6
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (1)

HIGHCVE-2026-14191EXP
WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader
Trending: 1

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Aug 8, 2025
Added to CISA KEV
Aug 8, 2025
Discovered by ZDM
Apr 1, 2026
Updated: cweIds
Jun 1, 2026
Updated: description, cweIds, tags
Jun 2, 2026
Updated: description, tags
Jun 9, 2026
Updated: description, cweIds, tags
Jun 9, 2026
Updated: description, tags
Jun 29, 2026
Actively Exploited
Aug 11, 2026
Exploit Available
Aug 11, 2026
Patch Available
Aug 11, 2026

Version History

v6
Last enriched 44d ago
v6Tier D44d ago

Updated description with new details on the exploitation method and added new IoCs and tags related to the ongoing attacks.

descriptiontags
via The Hacker News
v5Tier D64d ago

Updated description with details on two separate campaigns and added new CWE and MITRE ATT&CK technique.

descriptioncweIdstags
via Dark Reading
v4Tier D64d ago

Updated description with new attribution to Earth Dahu and SHADOW-EARTH-066 and added new tags related to cyber attacks in Ukraine.

descriptiontags
via The Hacker News
v3Tier D70d ago

Updated description with details on Gamaredon's exploitation of the vulnerability and added new CWE, IoCs, and tags.

descriptioncweIdstags
via The Hacker News
v2Tier D72d ago

Updated description with additional technical details and added CWE-22, while confirming the patch is version 7.13 or later.

cweIds
via Infosecurity Magazine
v1132d ago

Initial creation