CVE-2025-6218
9.5 CISA KEVRARLAB · WinRAR
RARLAB WinRAR contains a path traversal vulnerability that can lead to remote code execution. Attackers exploit improper file path handling in archives to execute code when a user opens a malicious file.
Executive summary
A critical path traversal vulnerability in WinRAR is currently being actively exploited in the wild, posing an immediate risk of remote code execution.
Vulnerability
The flaw exists within the handling of file paths within archive files, allowing for a directory traversal attack. An attacker can craft an archive that, when opened by a user, writes files to unintended locations, enabling the execution of arbitrary code in the context of the current user.
Business impact
Successful exploitation of this vulnerability grants an attacker the ability to execute arbitrary code with the privileges of the user running the WinRAR application. Given the CVSS score of 9.5, this is a critical risk that could lead to full system compromise, data theft, and the deployment of ransomware or other malicious payloads. The active exploitation of this flaw by multiple advanced threat actors significantly increases the likelihood of a successful targeted attack against organizational assets.
Remediation
Immediate Action: Update all installations of WinRAR to version 7.12 or later immediately to mitigate the underlying path traversal flaw.
Proactive Monitoring: Monitor endpoint logs for the execution of unexpected processes originating from the WinRAR application directory or associated temporary folders.
Compensating Controls: Implement strict email filtering to block incoming RAR archives from untrusted sources and utilize endpoint detection and response (EDR) solutions to identify and alert on suspicious file write operations performed by WinRAR.
Exploitation status
Public Exploit Available: Yes, multiple public proofs-of-concept are available on GitHub and the vulnerability is well-documented by security researchers.
Analyst recommendation
The severity of this vulnerability, combined with its status in the CISA Known Exploited Vulnerabilities catalog and evidence of active exploitation by multiple threat groups, necessitates an emergency patching response. Organizations should prioritize the deployment of WinRAR 7.12 across all workstations and servers. Failure to patch these systems leaves the environment vulnerable to remote code execution and potential long-term persistence by sophisticated adversaries.
More RARLAB CVEs
Sources
- ZDI-25-409
- vendor-provided URL Vendor advisory