Skip to content
Appaloosa Scout

KEV · Actively exploited

CVE-2025-8088

HIGH 8.8 KEV

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček
from ESET.

Attack vector : Network No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS 94.55% exploit likely percentile 99.8%

CISA Known Exploited Vulnerability

Added to KEV
2025-08-12
Remediation deadline
2025-09-02
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Ransomware
Yes, known ransomware campaign

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • WinRAR Windows winget:RARLab.WinRAR
    Affected <7.13 Fixed in 7.13 Latest tracked 7.23.0 patched
Vulnerable CPE configurations (1)
Vendor Product Versions
rarlab winrar
All platforms (wildcard)
<7.13
View on NVD ↗ CISA KEV catalog ↗ Advisory · www.vicarius.io