CVE-2025-8088
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.
CISA KEV
- Vendor
- RARLAB
- Product
- WinRAR
- Due date
- 2025-09-02
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=283&cHash=a64b4a8f662d3639dec8d65f47bc93c5 ; https://nvd.nist.gov/vuln/detail/CVE-2025-8088
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.