CVE-2025-8088 – WinRAR Path Traversal Exploit

·

·

3–4 minutes

Executive Summary

CVE-2025-8088 is a high-severity path traversal flaw in WinRAR for Windows (≤ 7.12). Exploited as a zero-day by Russian APT groups RomCom and Paper Werewolf, the bug allows arbitrary file placement and execution when victims open malicious RAR archives.

  • CVSS: 8.4 (high)
  • Affected Products: WinRAR ≤ 7.12, UnRAR.dll, portable UnRAR code (Windows only)
  • Impact: Remote code execution, persistence via autorun folders
  • Patch: Fixed in WinRAR 7.13 (July 30, 2025)
  • Urgency: CISA mandates federal patching by Sep 2, 2025

Vulnerability Overview

The flaw stems from improper validation of file paths during RAR extraction. Attackers craft archives with ..\ sequences and Alternate Data Streams (ADSes) to bypass directory restrictions.

  • Files can be silently written into Startup or other sensitive directories.
  • Malicious payloads (DLL, EXE, LNK, scripts) auto-execute on login.
  • Linux and Android builds are not affected.

Russian APT groups exploited this vulnerability as a zero-day before a patch existed. Organizations still running unpatched WinRAR — or without a process for tracking active zero-day exploitation — are exposed right now.

Noorstream delivers threat intelligence, vulnerability management, and offensive security assessments for high-risk environments.

→ Book a Strategic Security Briefing

Attack Vector

  • Delivered via phishing campaigns disguised as job applications, government forms, or resumes.
  • Decoy files (e.g., resume.txt) mask hidden malicious payloads in ADS.
  • On extraction, payloads land in autorun folders, ensuring persistence and remote access.

Exploitation Status

  • In the Wild: Active exploitation confirmed since July 18, 2025.
  • Actors: RomCom (Storm-0978) and Paper Werewolf (GOFFEE).
  • Campaigns: Financial, defense, logistics, manufacturing targets in Europe, Canada, Russia, Uzbekistan.
  • Dark Web: Exploit sold for ~$80,000 prior to attacks.
  • PoC: Multiple GitHub proofs-of-concept published.
  • CISA KEV: Added with mandatory patch deadline.

Mitigation Steps

  1. Patch Immediately – Update to WinRAR 7.13 or later across all systems.
  2. File Hunts – Scan for suspicious .lnk, .exe, .dll in %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup.
  3. Process Monitoring – Flag abnormal process launches tied to archive extraction.
  4. Controls – Restrict executable launches from %TEMP% and user-writable directories.
  5. Email Security – Sandbox RAR archives; block untrusted archive attachments.
  6. User Awareness – Train staff to treat unexpected RAR job applications as suspect.

High-Risk Indicators

Indicator Type: File Path
Value: ..\Startup\malware.lnk
Confidence: High

Indicator Type: Hash
Value: 45d7a1c99f2b3b48b1cfd88a9d9a1a33 (example RomCom LNK)
Confidence: Medium

Indicator Type: Process Behavior
Value: Archive extraction → Startup autorun injection
Confidence: High

Executive Summary

CVE-2025-8088 is a high-severity path traversal flaw in WinRAR for Windows (≤ 7.12). Exploited as a zero-day by Russian APT groups RomCom and Paper Werewolf, the bug allows arbitrary file placement and execution when victims open malicious RAR archives.

  • CVSS: 8.4 (high)
  • Affected Products: WinRAR ≤ 7.12, UnRAR.dll, portable UnRAR code (Windows only)
  • Impact: Remote code execution, persistence via autorun folders
  • Patch: Fixed in WinRAR 7.13 (July 30, 2025)
  • Urgency: CISA mandates federal patching by Sep 2, 2025

Vulnerability Overview

The flaw stems from improper validation of file paths during RAR extraction. Attackers craft archives with ..\ sequences and Alternate Data Streams (ADSes) to bypass directory restrictions.

  • Files can be silently written into Startup or other sensitive directories.
  • Malicious payloads (DLL, EXE, LNK, scripts) auto-execute on login.
  • Linux and Android builds are not affected.

Attack Vector

  • Delivered via phishing campaigns disguised as job applications, government forms, or resumes.
  • Decoy files (e.g., resume.txt) mask hidden malicious payloads in ADS.
  • On extraction, payloads land in autorun folders, ensuring persistence and remote access.

Exploitation Status

  • In the Wild: Active exploitation confirmed since July 18, 2025.
  • Actors: RomCom (Storm-0978) and Paper Werewolf (GOFFEE).
  • Campaigns: Financial, defense, logistics, manufacturing targets in Europe, Canada, Russia, Uzbekistan.
  • Dark Web: Exploit sold for ~$80,000 prior to attacks.
  • PoC: Multiple GitHub proofs-of-concept published.
  • CISA KEV: Added with mandatory patch deadline.

Mitigation Steps

  1. Patch Immediately – Update to WinRAR 7.13 or later across all systems.
  2. File Hunts – Scan for suspicious .lnk, .exe, .dll in %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup.
  3. Process Monitoring – Flag abnormal process launches tied to archive extraction.
  4. Controls – Restrict executable launches from %TEMP% and user-writable directories.
  5. Email Security – Sandbox RAR archives; block untrusted archive attachments.
  6. User Awareness – Train staff to treat unexpected RAR job applications as suspect.

High-Risk Indicators

Indicator Type: File Path
Value: ..\Startup\malware.lnk
Confidence: High

Indicator Type: Hash
Value: 45d7a1c99f2b3b48b1cfd88a9d9a1a33 (example RomCom LNK)
Confidence: Medium

Indicator Type: Process Behavior
Value: Archive extraction → Startup autorun injection
Confidence: High

Latest Exploited Vulnerabilities

  • CVE-2026-16232
    Check Point SmartConsole Improper Authentication Vulnerability
    Vendor: Check Point
    Affected Product: SmartConsole
    Exploit Confirmed: 2026-07-22
  • CVE-2026-50522
    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
    Vendor: Microsoft
    Affected Product: SharePoint
    Exploit Confirmed: 2026-07-22
  • CVE-2026-60137
    WordPress Core SQL Injection Vulnerability
    Vendor: WordPress
    Affected Product: Core
    Exploit Confirmed: 2026-07-21
  • CVE-2026-63030
    WordPress Core Interpretation Conflict Vulnerability
    Vendor: WordPress
    Affected Product: Core
    Exploit Confirmed: 2026-07-21
  • CVE-2026-0770
    Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
    Vendor: Langflow
    Affected Product: Langflow
    Exploit Confirmed: 2026-07-21

The Team Behind This Research Runs Every Briefing



© 2026 Noorstream Security. All Rights Reserved.

Discover more from Noorstream Security

Subscribe now to keep reading and get access to the full archive.

Continue reading