WinRAR Zero-Day Under Active Exploitation – Update to Latest Version Immediately
Aug 11, 2025
Zero-Day / Vulnerability
 The maintainers of the WinRAR file archiving utility have released an update to address an actively exploited zero-day vulnerability.  Tracked as CVE-2025-8088  (CVSS score: 8.8), the issue has been described as a case of path traversal affecting the Windows version of the tool that could be exploited to obtain arbitrary code execution by crafting malicious archive files.  "When extracting a file, previous versions of WinRAR, Windows versions of RAR, UnRAR, portable UnRAR source code and UnRAR.dll can be tricked into using a path, defined in a specially crafted archive, instead of a specified path," WinRAR said  in an advisory.  Anton Cherepanov, Peter Kosinar, and Peter Strycek from ESET have been credited for discovering and reporting the security defect, which has been addressed in WinRAR version 7.13 released on July 30, 2025.   The development is the second time a WinRAR security vulnerability has been weaponized in the wild in as many years. In 2023, another vulnerabil...