Vulnerability Details CVE-2025-8088
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strý?ek
from ESET.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.133
EPSS Ranking 93.9%
CVSS Severity
CVSS v3 Score 8.8
Proposed Action
RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.
Ransomware Campaign
Unknown
Products affected by CVE-2025-8088
-
cpe:2.3:a:rarlab:winrar:-
-
cpe:2.3:a:rarlab:winrar:4.00
-
cpe:2.3:a:rarlab:winrar:4.01
-
cpe:2.3:a:rarlab:winrar:4.1.0
-
cpe:2.3:a:rarlab:winrar:4.10
-
cpe:2.3:a:rarlab:winrar:4.10.2
-
cpe:2.3:a:rarlab:winrar:4.11
-
cpe:2.3:a:rarlab:winrar:4.20
-
cpe:2.3:a:rarlab:winrar:5.00
-
cpe:2.3:a:rarlab:winrar:5.01
-
cpe:2.3:a:rarlab:winrar:5.10
-
cpe:2.3:a:rarlab:winrar:5.11
-
cpe:2.3:a:rarlab:winrar:5.20
-
cpe:2.3:a:rarlab:winrar:5.21
-
cpe:2.3:a:rarlab:winrar:5.30
-
cpe:2.3:a:rarlab:winrar:5.31
-
cpe:2.3:a:rarlab:winrar:5.40
-
cpe:2.3:a:rarlab:winrar:5.50
-
cpe:2.3:a:rarlab:winrar:5.70
-
cpe:2.3:a:rarlab:winrar:6.11
-
cpe:2.3:a:rarlab:winrar:6.20
-
cpe:2.3:a:rarlab:winrar:6.21
-
cpe:2.3:a:rarlab:winrar:6.23
-
cpe:2.3:a:rarlab:winrar:6.24
-
cpe:2.3:a:rarlab:winrar:7.00
-
cpe:2.3:a:rarlab:winrar:7.01
-
cpe:2.3:a:rarlab:winrar:7.10
-
cpe:2.3:a:rarlab:winrar:7.11
-
cpe:2.3:a:rarlab:winrar:7.12
-
cpe:2.3:o:microsoft:windows:-