logo

WinRAR CVE-2025-8088 explained

ID: 5b16d4ec-f9f3-5bec-932e-d385c5bc5340

STIX ID: report--5b16d4ec-f9f3-5bec-932e-d385c5bc5340

Feed Name: ThreatLocker Blog

Threat Score
72/100

Date Published: 2026-02-05

Date Updated: 2026-05-01

...
...

**WinRAR CVE-2025-8088 (<=7.12):** A directory-traversal in an NTFS alternate data stream allows malicious archives to cause WinRAR to write embedded payloads to arbitrary locations (e.g., Startup folder) during extraction, enabling persistence; scored CVSS 8.4 and patched in WinRAR 7.13, with recommendations to update, monitor execution-sensitive folders, and apply application control/behavioral detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.