CVE-2025-8088
HIGH
8,4
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: active
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH
8,8
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček
from ESET.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0308
Percentile
0,9th
Updated
EPSS Score Trend (Last 91 Days)
35
Path Traversal: '.../...//'
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Potential Impacts:
Read Files Or Directories
Modify Files Or Directories
Bypass Protection Mechanism
Applicable Platforms
All platforms may be affected
Application
Dtsearch by Dtsearch
Version Range Affected
To
2023.01
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:dtsearch:dtsearch:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Winrar by Rarlab
Version Range Affected
To
7.13
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025…
https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-…
https://arstechnica.com/security/2025/08/high-severity-winrar-0-day-exploited-f…
https://support.dtsearch.com/faq/dts0245.htm
https://www.vicarius.io/vsociety/posts/cve-2025-8088-detect-winrar-zero-day
https://www.vicarius.io/vsociety/posts/cve-2025-8088-mitigate-winrar-zero-day-u…
https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=283&cHa…