CVE-2025-6218

Published Jun 21, 2025

Last updated 3 months ago

Overview

Description
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198.
Source
zdi-disclosures@trendmicro.com
NVD status
Analyzed
Products
winrar

Risk scores

CVSS 3.0

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
RARLAB WinRAR Path Traversal Vulnerability
Exploit added on
Dec 9, 2025
Exploit action due
Dec 30, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

zdi-disclosures@trendmicro.com
CWE-22

Social media

Hype score
Not currently trending
  1. 'Soporte_Tecnico_Nahuel.rar' seen from Argentina @abuse_ch CVE-2025-6218 and 8088 exploit. https://t.co/hLvq0p8T1P @1ZRR4H https://t.co/HlRFrehU4Y

    @smica83

    5 Mar 2026

    716 Impressions

    1 Retweet

    5 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  2. Top 5 Trending CVEs: 1 - CVE-2026-2648 2 - CVE-2026-1731 3 - CVE-2025-15556 4 - CVE-2025-49113 5 - CVE-2025-6218 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    21 Feb 2026

    94 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Top 5 Trending CVEs: 1 - CVE-2025-6218 2 - CVE-2025-52464 3 - CVE-2026-21509 4 - CVE-2026-20817 5 - CVE-2026-1731 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    20 Feb 2026

    104 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 'Dogovor.rar' seen from Ukraine @abuse_ch https://t.co/iLPdIbx85Z CVE-2025-8088, CVE-2025-6218 @500mk500 https://t.co/lBnDjzViPj

    @smica83

    16 Feb 2026

    174 Impressions

    0 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. #100DaysofYARA - Day 37 YARA rule to detect RAR samples exploiting CVE-2025-6218 👇 https://t.co/NWr5sWd6OP https://t.co/djifDZgME5

    @t3ft3lb

    6 Feb 2026

    276 Impressions

    1 Retweet

    6 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  6. '5_18_9_1328_03.02.2026.rar' seen from Ukraine as a CVE-2025-6218 and 8088 @abuse_ch https://t.co/bjJgnKkKnh Domains: hxxps://be42.khlgj68234.workers(.)dev/ hxxps://awokent5.ease.workers(.)dev/ hxxps://mobx2i.inquiries.workers(.)dev/ @_CERT_UA https://t.co/UxaA0MsVl6

    @smica83

    4 Feb 2026

    375 Impressions

    2 Retweets

    8 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  7. '4_11_2_1537_03.02.2026.rar' seen from Ukraine as CVE-2025-6218 and 8088 @abuse_ch https://t.co/MvZwIXXa1l @500mk500 https://t.co/pA2bcBhO3Z

    @smica83

    3 Feb 2026

    360 Impressions

    1 Retweet

    6 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  8. '1_12_8_1590_03.02.2026.rar' seen from Ukraine as a CVE-2025-6218 and 8088 @abuse_ch https://t.co/lFBhV85gbv @500mk500 https://t.co/8uEXo70Ivj

    @smica83

    3 Feb 2026

    344 Impressions

    0 Retweets

    7 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. '5_12_6_1292_02.02.2026.rar' seen from Ukraine as a CVE-2025-6218 and 8088 @abuse_ch https://t.co/zLPsDA1rMC @500mk500 https://t.co/mjKSWGoR0Y

    @smica83

    3 Feb 2026

    331 Impressions

    0 Retweets

    5 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  10. '4_14_1_1762_02.02.2026.rar' seen from Ukraine as a CVE-2025-6218 and 8088 exploit @abuse_ch https://t.co/GWaDBycLgd @500mk500 https://t.co/2BlVipmdRa

    @smica83

    2 Feb 2026

    533 Impressions

    1 Retweet

    7 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 'sample_credential zip' is a RAR archive, seen from Slovakia, Switzerland, Germany and the UK @abuse_ch https://t.co/eP1rYySPA1 CVE-2025-6218 and 8088 exploit. URL: hxxps://raw.githubusercontent(.)com/stealabrainrotscripts-tech/DiscordBot/refs/heads/main/DiscordBot.txt https:

    @smica83

    26 Jan 2026

    1725 Impressions

    4 Retweets

    8 Likes

    1 Bookmark

    0 Replies

    1 Quote

  12. '1_18_1_1052_21.01.2026.rar' as a daily #Gamaredon seen from Ukraine @abuse_ch https://t.co/7Io7CFQ3M1 CVE-2025-6218 and 8088 exploit. @500mk500 https://t.co/Hkb1EGjcOQ

    @smica83

    21 Jan 2026

    434 Impressions

    1 Retweet

    5 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 'Coinbase Vmed Lines ( Data ) zip' @abuse_ch https://t.co/tq3b9h7nDL CVE-2025-6218 and 8088 exploit. https://t.co/O4p8tJQbRP

    @smica83

    17 Jan 2026

    435 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  14. Daily #Gamaredon seen from Ukraine. '1_11_5_1761_14.01.2026.rar' @abuse_ch https://t.co/SenYccRRd1 Usual CVE-2025-6218 and 8088 exploit. @500mk500 https://t.co/br5R0InJCh

    @smica83

    14 Jan 2026

    422 Impressions

    1 Retweet

    9 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  15. 'P_260112_1.rar' CVE-2025-6218 and 8088 exploit seen from Russia @abuse_ch https://t.co/jN7Rxoc7OR https://t.co/jULHMHDj6H

    @smica83

    13 Jan 2026

    1219 Impressions

    3 Retweets

    8 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  16. 'calling.rar' CVE-2025-6218 and 8088 exploit seen from Sweden @abuse_ch https://t.co/i0OEyBk2nf https://t.co/9NNwFlb6wb

    @smica83

    13 Jan 2026

    257 Impressions

    0 Retweets

    2 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  17. 'Ledger 2026 Global-e zip' as a RAR file, CVE-2025-6218 and 8088 exploit. Seen from Slovenia. @abuse_ch https://t.co/fRSw9J6D0C Maybe it's a campaign to take advantage of the Ledger Global-e data leak incident. @skocherhan https://t.co/M05ngaRQeE

    @smica83

    13 Jan 2026

    1050 Impressions

    1 Retweet

    6 Likes

    1 Bookmark

    0 Replies

    1 Quote

  18. #threatreport #LowCompleteness Defending Against Gamaredon: Practical Controls That Actually Work | 08-01-2026 Source: https://t.co/baIPrIFxnC Key details below ↓ 🧑‍💻Actors/Campaigns: Gamaredon 💀Threats: Spear-phishing_technique, Gamaload, 🔓CVEs: CVE-2025-6218

    @rst_cloud

    9 Jan 2026

    62 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 'solty_futerIL_doxxed_by_Lux.rar' a CVE-2025-6218 and 8088 exploit, seen from Israel @abuse_ch https://t.co/lnfYoY7YsK Source from: https://t.co/uth77MIkuX

    @smica83

    8 Jan 2026

    610 Impressions

    3 Retweets

    6 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  20. 16 new OPEN, 16 new PRO (16 + 0) GhostFrame, Lumma Stealer, several CVEs (CVE-2024-45242, CVE-2024-53939, CVE-2024-53940, CVE-2024-53944, CVE-2024-53942, CVE-2025-43989 and CVE-2025-6218) and more. Thanks @malware_traffic https://t.co/XeGOQ3ewuz

    @ET_Labs

    6 Jan 2026

    174 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 'salary_statistics.rar' seen from Viet Nam @abuse_ch https://t.co/HyELNalfFL CVE-2025-6218 and 8088 exploit. https://t.co/KwkEWU1qZf

    @smica83

    6 Jan 2026

    1510 Impressions

    8 Retweets

    25 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

  22. 'data zip' CVE-2025-6218 and CVE-2025-8088 exploit seen from Bulgaria @abuse_ch https://t.co/fF82GcFdN5 https://t.co/xl64oBbQme

    @smica83

    4 Jan 2026

    330 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 🚨Path Traversal Vulnerability in WinRAR (CVE-2025-6218) Exploit🚨 WinRAR ≤ 7.11 allows attackers to execute code via malicious RAR files. Update to v7.12 ASAP to stay secure! 🔗 Learn more: https://t.co/fJZGsyvw8R #CVE2025 #WinRAR #CyberSecurity #SecurityUpdate #PatchN

    @KillerFungi2022

    27 Dec 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. APT #Gamaredon christmas update from Ukraine, with CVE-2025-6218 and 8088 exploits. Samples @abuse_ch '1_11_2_1984_25.12.2025.rar' https://t.co/9jkk4bYoHZ '4_18_2_1955_25.12.2025.rar' https://t.co/zFyQjgXUG2 @500mk500 https://t.co/tcLjKJNTLX

    @smica83

    25 Dec 2025

    645 Impressions

    0 Retweets

    8 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  25. APT #Gamaredon daily update from Ukraine, with CVE-2025-6218 and 8088 exploits. Samples @abuse_ch '4_15_1_1675_22.12.2025.rar' https://t.co/7nY8JtrzZs '5_18_5_1980_22.12.2025.rar' https://t.co/D9ECj0ZORP @500mk500 @skocherhan https://t.co/yq3jV7RePL

    @smica83

    22 Dec 2025

    570 Impressions

    2 Retweets

    6 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  26. Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups The U.S. Cybersecurity and Infras 𝗦𝘁𝗮𝘆 𝗶𝗻𝗳𝗼𝗿𝗺𝗲𝗱. 𝗛𝗶𝘁 𝘁𝗵𝗲 𝗳𝗼𝗹𝗹𝗼𝘄 𝗯𝘂𝘁𝘁𝗼𝗻! @thehackersnews @edgeitech

    @Edgeitech

    19 Dec 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. APT #Gamaredon started operations again in Ukraine, with CVE-2025-6218 and 8088 exploits. Samples @abuse_ch '4_11_7_1113_19.12.2025.rar' https://t.co/SrURRp7wQG '1_11_9_1391_19.12.2025.rar' https://t.co/Nt8ZHYMNED @500mk500 @skocherhan https://t.co/KoAc0lPxXf

    @smica83

    19 Dec 2025

    943 Impressions

    7 Retweets

    12 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  28. Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups https://t.co/6Wiy8PhEo0 via @TheHackersNews

    @JackyChun96

    18 Dec 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. اذا كنت تستخدم برنامج WinRAR على نظام Windows، توقف عما تفعله حالاً. هناك ثغرة أمنية خطيرة للغاية (تحمل الرمز CVE-2025-6218) ي 🛡️ الحل (افعل هذا الآن): 1️⃣ افتح برنام

    @RYMufWU8AAKxgoh

    18 Dec 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 'heyfes.rar' seen from Finland @abuse_ch https://t.co/Ry07qpSh98 CVE-2025-6218 and 8088 exploit https://t.co/vsMJXNo1dS

    @smica83

    17 Dec 2025

    305 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. '4_5886570468093206183 (1).rar' is a CVE-2025-6218 and 8088 exploit. Seen from Germany @abuse_ch https://t.co/GGfz1wIg1K @skocherhan @500mk500 https://t.co/1VZdSWFOyg

    @smica83

    16 Dec 2025

    1134 Impressions

    3 Retweets

    11 Likes

    2 Bookmarks

    0 Replies

    1 Quote

  32. Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups WinRAR Vulnerability CVE-2025-6218: U.S. CISA warns of active exploitation, citing evidence of path traversal bug. CVSS score: 7.8. WinRAR users, take immediate action to patch and secure h

    @HackonomicNews

    13 Dec 2025

    37 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  33. 🚨 Urgent warning! A critical WinRAR vulnerability (CVE-2025-6218) is actively being exploited by multiple threat groups. Update your software NOW to stay safe! #WinRAR #CyberAttack https://t.co/dVB2aqkNrw

    @xcybersecnews

    12 Dec 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. CISA warns WinRAR CVE-2025-6218 is under active attack by multiple threat groups, requiring federal by Dec. 30, 2025.

    @1cebi

    12 Dec 2025

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. CISA WinRAR CVE-2025-6218 is under active attack by multiple threat groups, requiring federal fixes by Dec. 30, 2025.

    @JackilynMegham

    12 Dec 2025

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. 🛡️ WinRAR's CVE-2025-6218 vulnerability is still lurking around despite a patch! Don't let your files take a detour into danger—update now! #WinRAR #CVE2025 #CyberSecurity https://t.co/3EquR4Vn7j

    @windowsforum

    11 Dec 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. Microsoft's December finale patches 56 bugs across Windows—3 Critical, including Office preview pane RCEs (CVE-2025-62554/57). One zero-day (WinRAR path traversal CVE-2025-6218) already in the wild per CISA. Update stat! https://t.co/3rlacTmYyg #MicrosoftPatch #ZeroDay

    @ImperialTechSvc

    11 Dec 2025

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. ⚠️ 𝗖𝗜𝗦𝗔 𝗙𝗹𝗮𝗴𝘀 𝗪𝗶𝗻𝗥𝗔𝗥 𝗣𝗮𝘁𝗵 𝗧𝗿𝗮𝘃𝗲𝗿𝘀𝗮𝗹 (CVE‑2025‑6218) CVE-2025-6218 is a 𝗪𝗶𝗻𝗥𝗔𝗥 𝗽𝗮𝘁𝗵 𝘁𝗿𝗮𝘃𝗲𝗿𝘀𝗮𝗹 𝘃𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶

    @0x534c

    11 Dec 2025

    2149 Impressions

    6 Retweets

    39 Likes

    17 Bookmarks

    1 Reply

    0 Quotes

  39. WinRAR脆弱性 CVE-2025-6218 を複数グループが悪用中 https://t.co/QVjkF0vrS8 #Security #セキュリティー #ニュース

    @SecureShield_

    11 Dec 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups https://t.co/UMDZURGQZC @TheHackersNews aracılığıyla

    @DaisiCarol88

    10 Dec 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. #ITSecurity CVE-2025-6218 RARLAB WinRAR Path Traversal Vulnerability https://t.co/WHHLbNgIcf

    @seaarepea

    10 Dec 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. CISA adiciona falha crítica no WinRAR ao catálogo KEV: A vulnerabilidade CVE-2025-6218 permite execução remota de código via path traversal e está sendo explorada em campanhas de phishing por grupos como GOFFEE, Bitter e Gamaredon, afetando principalmente Windows. https://t

    @caveiratech

    10 Dec 2025

    54 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  43. The Hacker News - Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups https://t.co/icrHlNgKgg

    @buzz_sec

    10 Dec 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. 🚨 CVE-2025-6218: RARLAB WinRAR Path Traversal Vulnerability has been added to the CISA KEV Catalog CVSS: 7.8 https://t.co/9idGUAIgzL

    @DarkWebInformer

    10 Dec 2025

    4014 Impressions

    3 Retweets

    22 Likes

    7 Bookmarks

    1 Reply

    0 Quotes

  45. 🛡️ We added RARLAB WinRAR path traversal vulnerability CVE-2025-6218 & Microsoft Windows use after free vulnerability CVE-2025-62221 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattack

    @CISACyber

    9 Dec 2025

    5152 Impressions

    27 Retweets

    39 Likes

    10 Bookmarks

    1 Reply

    0 Quotes

  46. #threatreport #MediumCompleteness QuasarRAT Malware Campaign using CVE-2025-6218 | 02-12-2025 Source: https://t.co/rj9MBD5fui Key details below ↓ 💀Threats: Quasar_rat, Steganography_technique, Tinba, Kuaibu8, 🎯Victims: Coinme users 🏭Industry: Financial 🔓CVEs: ht

    @rst_cloud

    9 Dec 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. 'salary_staistics.rar' seen from Viet Nam @abuse_ch CVE-2025-6218 and CVE-2025-8088 exploit https://t.co/UHxOvLKO68 @skocherhan https://t.co/NEldvm0hEu

    @smica83

    7 Dec 2025

    5199 Impressions

    5 Retweets

    36 Likes

    14 Bookmarks

    0 Replies

    1 Quote

  48. Gamaredon #IOCs Update (CVE-2025-6218) https://t.co/2Al0Hb0y1R https://t.co/kpxbQ7prUg

    @blackorbird

    3 Dec 2025

    3380 Impressions

    7 Retweets

    31 Likes

    13 Bookmarks

    1 Reply

    0 Quotes

  49. Another #Gamaredon sample, seen from Ukraine. '1_11_2_1759_22.11.2025.rar' @abuse_ch CVE-2025-6218 and 8088 exploit. https://t.co/w4RthoDay9 @500mk500 https://t.co/MynufrbeC6

    @smica83

    25 Nov 2025

    604 Impressions

    3 Retweets

    8 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  50. '7_7_1_1454_22.11.2025.rar' seen from Ukraine @abuse_ch CVE-2025-6218 and 8088 exploit. #Gamaredon https://t.co/KvKR5lcjYW @500mk500 @skocherhan https://t.co/bxEK7GFhMb

    @smica83

    24 Nov 2025

    1100 Impressions

    2 Retweets

    16 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

Configurations