A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýcek
from ESET.
References
Configurations
Configuration 1 (hide)
AND |
|
History
18 Aug 2025, 13:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.vicarius.io/vsociety/posts/cve-2025-8088-detect-winrar-zero-day - Third Party Advisory | |
References | () https://www.vicarius.io/vsociety/posts/cve-2025-8088-mitigate-winrar-zero-day-using-srp-and-ifeo - Mitigation, Third Party Advisory |
15 Aug 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýcek from ESET. |
13 Aug 2025, 19:08
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
First Time |
Microsoft
Rarlab winrar Rarlab Microsoft windows |
|
CPE | cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
References | () https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/#the-discovery-of-cve-2025-8088 - Press/Media Coverage | |
References | () https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=283&cHash=a64b4a8f662d3639dec8d65f47bc93c5 - Release Notes |
13 Aug 2025, 01:00
Type | Values Removed | Values Added |
---|---|---|
Summary | A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strý?ek from ESET. |
12 Aug 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
08 Aug 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-08 12:15
Updated : 2025-08-18 13:08
NVD link : CVE-2025-8088
Mitre link : CVE-2025-8088
JSON object : View
Products Affected
rarlab
- winrar
microsoft
- windows
CWE
No CWE.