Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Attackers exploited a serious WinRAR flaw in Windows before it was patched. The issue was not a breach of WinRAR’s payment or licensing system: it was a path traversal vulnerability that could let a malicious archive place files outside the folder a user chose. RARLAB fixed CVE-2025-8088 in WinRAR 7.13, released July 30, 2025. If you use WinRAR or a Windows app that includes its UnRAR components, check that it is updated.

What happened in the WinRAR attacks?

CVE-2025-8088 allowed a specially crafted archive to bypass the selected extraction location and write files elsewhere on a Windows system. RARLAB described it as a critical directory traversal vulnerability affecting WinRAR and related Windows components. The vendor said it was distinct from an earlier vulnerability fixed in version 7.12. RARLAB’s WinRAR 7.13 release notes list July 30, 2025, as the release date and identify 7.13 as the fix for CVE-2025-8088.

The flaw was exploited before that update was available. ESET reported that it found a malicious archive on July 18, 2025, and observed spearphishing campaigns from July 18 through July 21 targeting financial, manufacturing, defense, and logistics companies in Europe and Canada. ESET attributed the campaign to Russia-aligned RomCom and described its aim as cyberespionage. ESET researcher Peter Strýček said, “On July 18, we observed a malicious DLL named msedge.dll in a RAR archive containing unusual paths that caught our attention.” ESET’s account of the campaign provides those details.

The exploitation did not stop when the patch was released. In a report dated January 27, 2026, Google Threat Intelligence Group described widespread exploitation by government-backed actors linked to Russia and China, as well as financially motivated actors. Google reported activity through December 2025 and January 2026, including attacks against systems that remained vulnerable after the fix was available. Those later attacks are better described as n-day exploitation: the flaw was known and patched, rather than a zero-day at that point. Google’s report describes the later activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Express Rip Free CD Ripper Software - Extract Audio in Perfect Digital Quality [PC Download]
  • Perfect quality CD digital audio extraction (ripping)
  • Fastest CD Ripper available
  • Extract audio from CDs to wav or Mp3
  • Extract many other file formats including wma, m4q, aac, aiff, cda and more
  • Extract many other file formats including wma, m4q, aac, aiff, cda and more

How could extracting an archive put files elsewhere?

Path traversal involves using specially formed paths to escape the folder an application is meant to use. In this case, an attacker could craft a RAR archive so that extracting it wrote a file to an unintended location rather than only to the folder selected by the user.

Google describes observed archives that combined directory traversal characters with Windows Alternate Data Streams (ADS). In one pattern, a visible file acted as a decoy while a hidden stream carried a malicious file. The traversal could place a shortcut or script in the user’s Windows Startup folder, where it could run the next time the user logged in. That is one observed technique, not proof that every attack used the same archive contents or execution chain.

Rank #2
RAR for Android
  • Full RAR, RAR5 and ZIP support
  • Decompress RAR, RAR5, ZIP, TAR, GZ, BZ2, XZ, 7z, ISO and ARJ.
  • Password Protection
  • Simple File Management with 'cut', 'copy', 'delete', 'rename' and 'create folder' operations
  • White and black background colour schemes

The vulnerable software did not infect a PC simply by being installed. The reported attack required a victim to open or extract a malicious archive. Because a crafted archive could place files in locations the user did not intend, however, choosing a familiar extraction folder was not a reliable defense against this flaw.

Which WinRAR versions and components were affected?

For CVE-2025-8088, RARLAB lists these affected Windows components:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • WinRAR for Windows
  • RAR and UnRAR for Windows
  • UnRAR.dll
  • Portable UnRAR for Windows

The Canadian Centre for Cyber Security likewise says versions before 7.13 were affected and recommends applying the update. RARLAB says Linux/Unix builds and RAR for Android were not affected by CVE-2025-8088. These sources establish the scope of this specific flaw; they do not provide a comparative security assessment of other archive tools such as 7-Zip. The Canadian advisory summarizes the affected-version boundary and remediation.

How this differs from CVE-2025-6218

CVE-2025-6218 was a separate earlier directory traversal vulnerability, not another name for CVE-2025-8088. CERT Santé said versions before WinRAR 7.12 Beta 1 were affected by CVE-2025-6218 and recommended updating to 7.12 Beta 1 or later. RARLAB’s 7.13 notice explicitly distinguishes the later 8088 issue from the earlier bug. Thus, the 7.13 threshold addresses CVE-2025-8088 and is also newer than the cited 7.12 Beta 1 threshold for CVE-2025-6218. CERT Santé’s advisory covers CVE-2025-6218.

Rank #4
DeskFX Free Audio Effects & Audio Enhancer Software [PC Download]
  • Transform audio playing via your speakers and headphones
  • Improve sound quality by adjusting it with effects
  • Take control over the sound playing through audio hardware

How to check your version and update safely

  1. Check the installed version. Open WinRAR and select Help > About WinRAR. Note the version shown. If it is earlier than 7.13, it is below the patch threshold established for CVE-2025-8088.
  2. Get the current release from RARLAB. Use the official WinRAR download page, choose the appropriate Windows package, and install it. Version 7.13 is the documented fix threshold for CVE-2025-8088; the sources cited here do not establish that 7.13 is the latest release as of October 4, 2026, so check the official page for the current version.
  3. Check more than the desktop app. Administrators should inventory Windows RAR and UnRAR tools, UnRAR.dll, portable UnRAR, and applications that embed affected UnRAR code. Updating the WinRAR interface alone may not update a separate bundled component.

An old paid license does not patch software automatically, and the passage of time does not make an unpatched installation safe. Use RARLAB’s official distribution channel to obtain an update rather than relying on a license status or an old installer.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is WinRAR safe now?

Installing a release that fixes CVE-2025-8088 prevents exploitation of this known flaw through the affected software. It cannot show whether an older installation was compromised before it was updated. If you have signs that a malicious archive may have been handled, or find unexpected files in a Windows Startup folder, follow your organization’s incident-response process or seek appropriate security assistance. Google’s report includes indicators of compromise for defenders.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 1
Express Rip Free CD Ripper Software - Extract Audio in Perfect Digital Quality [PC Download]
Express Rip Free CD Ripper Software - Extract Audio in Perfect Digital Quality [PC Download]
Perfect quality CD digital audio extraction (ripping); Fastest CD Ripper available; Extract audio from CDs to wav or Mp3
Bestseller No. 2
RAR for Android
RAR for Android
Full RAR, RAR5 and ZIP support; Decompress RAR, RAR5, ZIP, TAR, GZ, BZ2, XZ, 7z, ISO and ARJ.
Bestseller No. 3
Bestseller No. 4
DeskFX Free Audio Effects & Audio Enhancer Software [PC Download]
DeskFX Free Audio Effects & Audio Enhancer Software [PC Download]
Transform audio playing via your speakers and headphones; Improve sound quality by adjusting it with effects
Bestseller No. 5
Free Fling File Transfer Software for Windows [PC Download]
Free Fling File Transfer Software for Windows [PC Download]
Intuitive interface of a conventional FTP client; Easy and Reliable FTP Site Maintenance.; FTP Automation and Synchronization
Best Value
Free Fling File Transfer Software for Windows [PC Download]
  • Intuitive interface of a conventional FTP client
  • Easy and Reliable FTP Site Maintenance.
  • FTP Automation and Synchronization

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.