WinRAR releases emergency patch for serious security vulnerability, users need to update immediately

Last week, WinRAR version 7.13 was released, fixing a directory traversal vulnerability, tracked under the identifier CVE-2025-8088.

Last week, WinRAR version 7.13 was released, fixing a directory traversal vulnerability, which is tracked as CVE-2025-8088. Thanks to researchers from ESET, we now have more details on how to exploit this vulnerability, especially since some hacker groups are actively using it for malicious purposes.

 

Specifically, this vulnerability lies in the core library UNRAR.dll, which is responsible for decompressing files. Hackers create a malicious compressed file that can 'trick' the software into writing files to a location of their choice instead of the folder specified by the user.

When unpacking, earlier versions of WinRAR, WinRAR on Windows, UnRAR, UnRAR portable source code and UnRAR.dll can be tricked into using a path defined in a special archive instead of a user-selected path.

According to ESET experts Anton Cherepanov, Peter Košinár, and Peter Strýček, attackers exploit this vulnerability to insert payloads into sensitive locations in the system, such as the Startup folder. By placing an executable file in %APPDATA%MicrosoftWindowsStart MenuProgramsStartup , the malicious code will automatically run when the user logs in, allowing hackers to execute code remotely on the compromised machine.

The group behind these attacks is believed to be the 'RomCom crew'. The RomCom malware is a Remote Access Trojan (RAT) that has been active since at least 2022. It uses social engineering to trick users, even impersonating popular software websites like KeePass, to trick victims into downloading the RAT installer. This hacking group has primarily targeted countries like Ukraine and some NATO members.

This is not the first time WinRAR has faced a serious security issue this year. Previously, version 7.12 patched a similar vulnerability (CVE-2025-6218) that affected WinRAR 7.11 and earlier versions.

According to Bleeping Computer, WinRAR does not have a built-in automatic update mechanism, so users must proactively access the official website to download and install version 7.13 to ensure safety. WinRAR also confirmed that the Unix versions of RAR and UnRAR, along with RAR for Android, will not be affected.

Other Technology story articles
Category

System

Windows XP

Windows Server 2012

Windows 8

Windows 7

Windows 10

Wifi tips

Virus Removal - Spyware

Speed ​​up the computer

Server

Security solution

Mail Server

LAN - WAN

Ghost - Install Win

Fix computer error

Configure Router Switch

Computer wallpaper

Computer security

Mac OS X

Mac OS System software

Mac OS Security

Mac OS Office application

Mac OS Email Management

Mac OS Data - File

Mac hardware

Hardware

USB - Flash Drive

Speaker headset

Printer

PC hardware

Network equipment

Laptop hardware

Computer components

Advice Computer

Game

PC game

Online game

Mobile Game

Pokemon GO

information

Technology story

Technology comments

Quiz technology

New technology

British talent technology

Attack the network

Artificial intelligence

Technology

Smart watches

Raspberry Pi

Linux

Camera

Basic knowledge

Banking services

SEO tips

Science

Strange story

Space Science

Scientific invention

Science Story

Science photo

Science and technology

Medicine

Health Care

Fun science

Environment

Discover science

Discover nature

Archeology

Life

Travel Experience

Tips

Raise up child

Make up

Life skills

Home Care

Entertainment

DIY Handmade

Cuisine

Christmas

Application

Web Email

Website - Blog

Web browser

Support Download - Upload

Software conversion

Social Network

Simulator software

Online payment

Office information

Music Software

Map and Positioning

Installation - Uninstall

Graphic design

Free - Discount

Email reader

Edit video

Edit photo

Compress and Decompress

Chat, Text, Call

Archive - Share

Electric

Water heater

Washing machine

Television

Machine tool

Fridge

Fans

Air conditioning

Program

Unix and Linux

SQL Server

SQL

Python

Programming C

PHP

NodeJS

MongoDB

jQuery

JavaScript

HTTP

HTML

Git

Database

Data structure and algorithm

CSS and CSS3

C ++

C #

AngularJS

Mobile

Wallpapers and Ringtones

Tricks application

Take and process photos

Storage - Sync

Security and Virus Removal

Personalized

Online Social Network

Map

Manage and edit Video

Data

Chat - Call - Text

Browser and Add-on

Basic setup