CVE CVE

CVE-2025-8088

CISA Known Exploited Vulnerability (KEV)

RARLAB WinRAR Path Traversal Vulnerability

August 12, 2025

September 2, 2025

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček
from ESET.

Weakness Enumeration

CWE-ID CWE Name

CWE-35
Path Traversal: ‘…/…//’

Known Affected Software Configurations


cpe:2.3:a:dtsearch:dtsearch:2021.01:build8712:*:*:*:*:*:*

cpe:2.3:a:dtsearch:dtsearch:2021.02:build8730:*:*:*:*:*:*

cpe:2.3:a:dtsearch:dtsearch:2021.02:build8733:*:*:*:*:*:*

cpe:2.3:a:dtsearch:dtsearch:2022.01:build8748:*:*:*:*:*:*

cpe:2.3:a:dtsearch:dtsearch:2022.01:build8749:*:*:*:*:*:*

cpe:2.3:a:dtsearch:dtsearch:2022.02:build8775:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:6.23:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:6.24:-:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:6.24:beta1:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:7.00:-:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:7.00:beta1:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:7.00:beta2:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:7.00:beta3:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:7.00:beta4:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:7.01:-:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:7.01:beta1:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:7.10:-:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:7.10:beta1:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:7.10:beta2:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:7.10:beta3:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:7.11:-:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:7.11:beta1:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:7.12:beta1:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:6.21:-:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:6.21:beta1:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:6.20:-:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:6.20:beta1:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:6.20:beta2:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:6.20:beta3:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:6.11:*:*:*:*:*:*:*

cpe:2.3:a:dtsearch:dtsearch:7.90.8538.1:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:5.70:beta1:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:5.50:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:5.40:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:5.31:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:5.30:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:5.21:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:5.20:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:5.11:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:5.10:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:5.01:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:5.00:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:4.20:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:4.11:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:4.10:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:4.01:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:4.00:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:5.30:beta_4:*:*:*:*:x64:*

cpe:2.3:a:rarlab:winrar:5.30:beta_4:*:*:*:*:x86:*

cpe:2.3:a:rarlab:winrar:4.10.2:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:4.1.0:*:*:*:*:*:x64:*

cpe:2.3:a:rarlab:winrar:4.1.0:*:*:*:*:*:*:*

cpe:2.3:a:dtsearch:dtsearch:7.66.7936:*:*:*:*:*:*:*

cpe:2.3:a:rarlab:winrar:-:*:*:*:*:*:*:*

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
8.8
Severity:

HIGH

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2

Not defined