CVE-2025-8088 is a critical path traversal vulnerability in the Windows version of WinRAR, allowing attackers to execute arbitrary code through specially crafted archive files. With a CVSS score of 8.8 (HIGH), this flaw has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. Discovered by ESET, this vulnerability is actively exploited in the wild, as evidenced by its inclusion in the KEV catalog and numerous reports of its use in phishing attacks to deploy malware like Amaranth Loader and Havoc Framework. While no public exploit modules exist in Metasploit or ExploitDB, the high level of community discussion and media coverage underscores its significant threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.13CPE matchmatch criteria | cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:* | ||
< 2023.01CPE matchmatch criteria | cpe:2.3:a:dtsearch:dtsearch:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.