HackerFeeds
All CVEs

CVE-2025-8088

HIGH8.8
CISA KEV

Published 2025-08-08 · Updated 2026-08-11 · Source security@eset.com

Description

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CWE-35

CISA Known-Exploited Vulnerability

Product: RARLABWinRAR

Name: RARLAB WinRAR Path Traversal Vulnerability

Date added: 2025-08-12 · Due: 2025-09-02

USED IN RANSOMWARE

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

View on NVD