AI description
CVE-2025-6218 is a directory traversal remote code execution vulnerability that affects RARLAB WinRAR. It allows remote attackers to execute arbitrary code on affected installations. Exploitation of this vulnerability requires user interaction, as the target must visit a malicious page or open a malicious file. The vulnerability lies in how WinRAR handles file paths within archive files, where a specially crafted file path can cause the process to traverse to unintended directories. By leveraging this vulnerability, an attacker can execute code within the security context of the current user.
- Description
- RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198.
- Source
- zdi-disclosures@trendmicro.com
- NVD status
- Analyzed
- Products
- winrar
CVSS 3.0
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- RARLAB WinRAR Path Traversal Vulnerability
- Exploit added on
- Dec 9, 2025
- Exploit action due
- Dec 30, 2025
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- zdi-disclosures@trendmicro.com
- CWE-22
- Hype score
- Not currently trending
'oxmaul.rar' seen from Latvia @abuse_ch ffa5c396a37ef0dbabf541cecc4e1bda84675eace39d2a8d2ccf355f08a9ca80 https://t.co/PZqxt2AXhy CVE-2025-6218 and 8088 exploit. https://t.co/uKkZFwRcKW
@smica83
27 Jul 2026
529 Impressions
3 Retweets
4 Likes
1 Bookmark
0 Replies
0 Quotes
'penis.11' is a ZIP, seen from Poland @abuse_ch CVE-2025-6218 and 8088 exploit. Some kind of Ransomware in it. 4472b8c557a3b5ad7b4a83034a4f7a40269074088bfde6902eda066c7dbfe77b https://t.co/RfLAQ38VkM https://t.co/9AKEoGWe6j
@smica83
23 Jun 2026
453 Impressions
3 Retweets
3 Likes
1 Bookmark
0 Replies
0 Quotes
๐จ #ThreatIntel: New cyber espionage campaign targeting Pakistan's defense sector (Ministry of Defence / Air Force) ๐ต๐ฐ An @anyrun_app sample reveals a malicious ZIP archive leveraging a WinRAR Path Traversal vulnerability (CVE-2025-6218) with NTFS Alternate Data Streams
@askardyuss
18 Jun 2026
528 Impressions
0 Retweets
5 Likes
1 Bookmark
0 Replies
0 Quotes
#APT #Sidewinder | #New #Variant | Targets #Pakistan Initial Dropper -> WinRAR ADS traversal vulnerabilities (CVE-2025-6218 & CVE-2025-8088) Decoy https://epms[.]ppra[.]gov[.]pk/public/tenders/invoice/TS0000000101E C2: docs.files-windows[.]top/j658K @500mk500 @MichalKo
@volrant136
14 May 2026
1176 Impressions
6 Retweets
16 Likes
6 Bookmarks
1 Reply
0 Quotes
'4_13_1_1389_28.04.2026.rar' @abuse_ch https://t.co/zlfXu4PgOA CVE-2025-6218, 8088 exploit. @500mk500 https://t.co/fYQDzyxioI
@smica83
13 May 2026
739 Impressions
4 Retweets
6 Likes
2 Bookmarks
0 Replies
0 Quotes
CVE-2025-6218-POC - WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of WinRAR https://t.co/GtJ8Ub8tor
@1024Cyber
7 May 2026
262 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
'ideasserverRUST.rar' seen from Spain @abuse_ch CVE-2025-6218 and 8088 exploit https://t.co/d2ylFFj1zK https://t.co/PCAuuNtBZS
@smica83
14 Apr 2026
282 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
Robin Dost analyses a UAC-0226 sample, identifying it as a GIFTEDCROOK stealer variant. The chain starts with CVE-2025-6218 & CVE-2025-8088; a LNK launches a payload that decodes a binary, uses chunked data exfiltration & reconstructs its C2 at runtime. https://t.co/aYxPm
@virusbtn
10 Apr 2026
818 Impressions
1 Retweet
7 Likes
2 Bookmarks
0 Replies
0 Quotes
โฆ๏ธ Exposed #opendir on 187.77.173[.]118 port 8080 hosting AI-generated tools to analyze CVE-2025-6218 and test bypass variants against the official patch for WinRAR(?). The environment includes progress tracking and references to a business model aligned with 0-day developme
@1ZRR4H
19 Mar 2026
13293 Impressions
16 Retweets
91 Likes
46 Bookmarks
1 Reply
1 Quote
โฆ๏ธ Exposed #opendir on 187.77.173[.]118 port 8080 hosting AI-generated tools to analyze CVE-2025-6218 and test bypass variants against the official patch for WinRAR. The environment includes progress tracking and references to a business model aligned with 0-day development
@1ZRR4H
19 Mar 2026
73 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
'Soporte_Tecnico_Nahuel.rar' seen from Argentina @abuse_ch CVE-2025-6218 and 8088 exploit. https://t.co/hLvq0p8T1P @1ZRR4H https://t.co/HlRFrehU4Y
@smica83
5 Mar 2026
716 Impressions
1 Retweet
5 Likes
3 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2026-2648 2 - CVE-2026-1731 3 - CVE-2025-15556 4 - CVE-2025-49113 5 - CVE-2025-6218 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
21 Feb 2026
94 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2025-6218 2 - CVE-2025-52464 3 - CVE-2026-21509 4 - CVE-2026-20817 5 - CVE-2026-1731 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
20 Feb 2026
104 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
'Dogovor.rar' seen from Ukraine @abuse_ch https://t.co/iLPdIbx85Z CVE-2025-8088, CVE-2025-6218 @500mk500 https://t.co/lBnDjzViPj
@smica83
16 Feb 2026
174 Impressions
0 Retweets
4 Likes
0 Bookmarks
0 Replies
0 Quotes
#100DaysofYARA - Day 37 YARA rule to detect RAR samples exploiting CVE-2025-6218 ๐ https://t.co/NWr5sWd6OP https://t.co/djifDZgME5
@t3ft3lb
6 Feb 2026
276 Impressions
1 Retweet
6 Likes
1 Bookmark
0 Replies
0 Quotes
'5_18_9_1328_03.02.2026.rar' seen from Ukraine as a CVE-2025-6218 and 8088 @abuse_ch https://t.co/bjJgnKkKnh Domains: hxxps://be42.khlgj68234.workers(.)dev/ hxxps://awokent5.ease.workers(.)dev/ hxxps://mobx2i.inquiries.workers(.)dev/ @_CERT_UA https://t.co/UxaA0MsVl6
@smica83
4 Feb 2026
375 Impressions
2 Retweets
8 Likes
2 Bookmarks
0 Replies
0 Quotes
'4_11_2_1537_03.02.2026.rar' seen from Ukraine as CVE-2025-6218 and 8088 @abuse_ch https://t.co/MvZwIXXa1l @500mk500 https://t.co/pA2bcBhO3Z
@smica83
3 Feb 2026
360 Impressions
1 Retweet
6 Likes
1 Bookmark
0 Replies
0 Quotes
'1_12_8_1590_03.02.2026.rar' seen from Ukraine as a CVE-2025-6218 and 8088 @abuse_ch https://t.co/lFBhV85gbv @500mk500 https://t.co/8uEXo70Ivj
@smica83
3 Feb 2026
344 Impressions
0 Retweets
7 Likes
0 Bookmarks
0 Replies
0 Quotes
'5_12_6_1292_02.02.2026.rar' seen from Ukraine as a CVE-2025-6218 and 8088 @abuse_ch https://t.co/zLPsDA1rMC @500mk500 https://t.co/mjKSWGoR0Y
@smica83
3 Feb 2026
331 Impressions
0 Retweets
5 Likes
1 Bookmark
0 Replies
0 Quotes
'4_14_1_1762_02.02.2026.rar' seen from Ukraine as a CVE-2025-6218 and 8088 exploit @abuse_ch https://t.co/GWaDBycLgd @500mk500 https://t.co/2BlVipmdRa
@smica83
2 Feb 2026
533 Impressions
1 Retweet
7 Likes
0 Bookmarks
0 Replies
0 Quotes
'sample_credential zip' is a RAR archive, seen from Slovakia, Switzerland, Germany and the UK @abuse_ch https://t.co/eP1rYySPA1 CVE-2025-6218 and 8088 exploit. URL: hxxps://raw.githubusercontent(.)com/stealabrainrotscripts-tech/DiscordBot/refs/heads/main/DiscordBot.txt https:
@smica83
26 Jan 2026
1725 Impressions
4 Retweets
8 Likes
1 Bookmark
0 Replies
1 Quote
'1_18_1_1052_21.01.2026.rar' as a daily #Gamaredon seen from Ukraine @abuse_ch https://t.co/7Io7CFQ3M1 CVE-2025-6218 and 8088 exploit. @500mk500 https://t.co/Hkb1EGjcOQ
@smica83
21 Jan 2026
434 Impressions
1 Retweet
5 Likes
0 Bookmarks
0 Replies
0 Quotes
'Coinbase Vmed Lines ( Data ) zip' @abuse_ch https://t.co/tq3b9h7nDL CVE-2025-6218 and 8088 exploit. https://t.co/O4p8tJQbRP
@smica83
17 Jan 2026
435 Impressions
0 Retweets
2 Likes
1 Bookmark
1 Reply
0 Quotes
Daily #Gamaredon seen from Ukraine. '1_11_5_1761_14.01.2026.rar' @abuse_ch https://t.co/SenYccRRd1 Usual CVE-2025-6218 and 8088 exploit. @500mk500 https://t.co/br5R0InJCh
@smica83
14 Jan 2026
422 Impressions
1 Retweet
9 Likes
1 Bookmark
0 Replies
0 Quotes
'P_260112_1.rar' CVE-2025-6218 and 8088 exploit seen from Russia @abuse_ch https://t.co/jN7Rxoc7OR https://t.co/jULHMHDj6H
@smica83
13 Jan 2026
1219 Impressions
3 Retweets
8 Likes
3 Bookmarks
0 Replies
0 Quotes
'calling.rar' CVE-2025-6218 and 8088 exploit seen from Sweden @abuse_ch https://t.co/i0OEyBk2nf https://t.co/9NNwFlb6wb
@smica83
13 Jan 2026
257 Impressions
0 Retweets
2 Likes
3 Bookmarks
0 Replies
0 Quotes
'Ledger 2026 Global-e zip' as a RAR file, CVE-2025-6218 and 8088 exploit. Seen from Slovenia. @abuse_ch https://t.co/fRSw9J6D0C Maybe it's a campaign to take advantage of the Ledger Global-e data leak incident. @skocherhan https://t.co/M05ngaRQeE
@smica83
13 Jan 2026
1050 Impressions
1 Retweet
6 Likes
1 Bookmark
0 Replies
1 Quote
#threatreport #LowCompleteness Defending Against Gamaredon: Practical Controls That Actually Work | 08-01-2026 Source: https://t.co/baIPrIFxnC Key details below โ ๐งโ๐ปActors/Campaigns: Gamaredon ๐Threats: Spear-phishing_technique, Gamaload, ๐CVEs: CVE-2025-6218
@rst_cloud
9 Jan 2026
62 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
'solty_futerIL_doxxed_by_Lux.rar' a CVE-2025-6218 and 8088 exploit, seen from Israel @abuse_ch https://t.co/lnfYoY7YsK Source from: https://t.co/uth77MIkuX
@smica83
8 Jan 2026
610 Impressions
3 Retweets
6 Likes
1 Bookmark
0 Replies
0 Quotes
16 new OPEN, 16 new PRO (16 + 0) GhostFrame, Lumma Stealer, several CVEs (CVE-2024-45242, CVE-2024-53939, CVE-2024-53940, CVE-2024-53944, CVE-2024-53942, CVE-2025-43989 and CVE-2025-6218) and more. Thanks @malware_traffic https://t.co/XeGOQ3ewuz
@ET_Labs
6 Jan 2026
174 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
'salary_statistics.rar' seen from Viet Nam @abuse_ch https://t.co/HyELNalfFL CVE-2025-6218 and 8088 exploit. https://t.co/KwkEWU1qZf
@smica83
6 Jan 2026
1510 Impressions
8 Retweets
25 Likes
6 Bookmarks
0 Replies
0 Quotes
'data zip' CVE-2025-6218 and CVE-2025-8088 exploit seen from Bulgaria @abuse_ch https://t.co/fF82GcFdN5 https://t.co/xl64oBbQme
@smica83
4 Jan 2026
330 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
๐จPath Traversal Vulnerability in WinRAR (CVE-2025-6218) Exploit๐จ WinRAR โค 7.11 allows attackers to execute code via malicious RAR files. Update to v7.12 ASAP to stay secure! ๐ Learn more: https://t.co/fJZGsyvw8R #CVE2025 #WinRAR #CyberSecurity #SecurityUpdate #PatchN
@KillerFungi2022
27 Dec 2025
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
APT #Gamaredon christmas update from Ukraine, with CVE-2025-6218 and 8088 exploits. Samples @abuse_ch '1_11_2_1984_25.12.2025.rar' https://t.co/9jkk4bYoHZ '4_18_2_1955_25.12.2025.rar' https://t.co/zFyQjgXUG2 @500mk500 https://t.co/tcLjKJNTLX
@smica83
25 Dec 2025
645 Impressions
0 Retweets
8 Likes
1 Bookmark
0 Replies
0 Quotes
APT #Gamaredon daily update from Ukraine, with CVE-2025-6218 and 8088 exploits. Samples @abuse_ch '4_15_1_1675_22.12.2025.rar' https://t.co/7nY8JtrzZs '5_18_5_1980_22.12.2025.rar' https://t.co/D9ECj0ZORP @500mk500 @skocherhan https://t.co/yq3jV7RePL
@smica83
22 Dec 2025
570 Impressions
2 Retweets
6 Likes
3 Bookmarks
0 Replies
0 Quotes
Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups The U.S. Cybersecurity and Infras ๐ฆ๐๐ฎ๐ ๐ถ๐ป๐ณ๐ผ๐ฟ๐บ๐ฒ๐ฑ. ๐๐ถ๐ ๐๐ต๐ฒ ๐ณ๐ผ๐น๐น๐ผ๐ ๐ฏ๐๐๐๐ผ๐ป! @thehackersnews @edgeitech
@Edgeitech
19 Dec 2025
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
APT #Gamaredon started operations again in Ukraine, with CVE-2025-6218 and 8088 exploits. Samples @abuse_ch '4_11_7_1113_19.12.2025.rar' https://t.co/SrURRp7wQG '1_11_9_1391_19.12.2025.rar' https://t.co/Nt8ZHYMNED @500mk500 @skocherhan https://t.co/KoAc0lPxXf
@smica83
19 Dec 2025
943 Impressions
7 Retweets
12 Likes
2 Bookmarks
0 Replies
0 Quotes
Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups https://t.co/6Wiy8PhEo0 via @TheHackersNews
@JackyChun96
18 Dec 2025
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ุงุฐุง ููุช ุชุณุชุฎุฏู ุจุฑูุงู ุฌ WinRAR ุนูู ูุธุงู Windowsุ ุชููู ุนู ุง ุชูุนูู ุญุงูุงู. ููุงู ุซุบุฑุฉ ุฃู ููุฉ ุฎุทูุฑุฉ ููุบุงูุฉ (ุชุญู ู ุงูุฑู ุฒ CVE-2025-6218) ู ๐ก๏ธ ุงูุญู (ุงูุนู ูุฐุง ุงูุขู): 1๏ธโฃ ุงูุชุญ ุจุฑูุงู
@RYMufWU8AAKxgoh
18 Dec 2025
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
'heyfes.rar' seen from Finland @abuse_ch https://t.co/Ry07qpSh98 CVE-2025-6218 and 8088 exploit https://t.co/vsMJXNo1dS
@smica83
17 Dec 2025
305 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
'4_5886570468093206183 (1).rar' is a CVE-2025-6218 and 8088 exploit. Seen from Germany @abuse_ch https://t.co/GGfz1wIg1K @skocherhan @500mk500 https://t.co/1VZdSWFOyg
@smica83
16 Dec 2025
1134 Impressions
3 Retweets
11 Likes
2 Bookmarks
0 Replies
1 Quote
Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups WinRAR Vulnerability CVE-2025-6218: U.S. CISA warns of active exploitation, citing evidence of path traversal bug. CVSS score: 7.8. WinRAR users, take immediate action to patch and secure h
@HackonomicNews
13 Dec 2025
37 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
๐จ Urgent warning! A critical WinRAR vulnerability (CVE-2025-6218) is actively being exploited by multiple threat groups. Update your software NOW to stay safe! #WinRAR #CyberAttack https://t.co/dVB2aqkNrw
@xcybersecnews
12 Dec 2025
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA warns WinRAR CVE-2025-6218 is under active attack by multiple threat groups, requiring federal by Dec. 30, 2025.
@1cebi
12 Dec 2025
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA WinRAR CVE-2025-6218 is under active attack by multiple threat groups, requiring federal fixes by Dec. 30, 2025.
@JackilynMegham
12 Dec 2025
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
๐ก๏ธ WinRAR's CVE-2025-6218 vulnerability is still lurking around despite a patch! Don't let your files take a detour into dangerโupdate now! #WinRAR #CVE2025 #CyberSecurity https://t.co/3EquR4Vn7j
@windowsforum
11 Dec 2025
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft's December finale patches 56 bugs across Windowsโ3 Critical, including Office preview pane RCEs (CVE-2025-62554/57). One zero-day (WinRAR path traversal CVE-2025-6218) already in the wild per CISA. Update stat! https://t.co/3rlacTmYyg #MicrosoftPatch #ZeroDay
@ImperialTechSvc
11 Dec 2025
57 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
โ ๏ธ ๐๐๐ฆ๐ ๐๐น๐ฎ๐ด๐ ๐ช๐ถ๐ป๐ฅ๐๐ฅ ๐ฃ๐ฎ๐๐ต ๐ง๐ฟ๐ฎ๐๐ฒ๐ฟ๐๐ฎ๐น (CVEโ2025โ6218) CVE-2025-6218 is a ๐ช๐ถ๐ป๐ฅ๐๐ฅ ๐ฝ๐ฎ๐๐ต ๐๐ฟ๐ฎ๐๐ฒ๐ฟ๐๐ฎ๐น ๐๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ
@0x534c
11 Dec 2025
2149 Impressions
6 Retweets
39 Likes
17 Bookmarks
1 Reply
0 Quotes
WinRAR่ๅผฑๆง CVE-2025-6218 ใ่คๆฐใฐใซใผใใๆช็จไธญ https://t.co/QVjkF0vrS8 #Security #ใปใญใฅใชใใฃใผ #ใใฅใผใน
@SecureShield_
11 Dec 2025
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups https://t.co/UMDZURGQZC @TheHackersNews aracฤฑlฤฑฤฤฑyla
@DaisiCarol88
10 Dec 2025
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E5B3E0ED-B444-468E-804E-7664C75CE9EA",
"versionEndExcluding": "7.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]