8.8 CVE-2025-8088

CISA Kev Catalog
 

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.
https://nvd.nist.gov/vuln/detail/CVE-2025-8088

Categories

CWE-35

References


 

CPE

cpe start end
Configuration 1
AND
   cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:* < 7.13
  Running on/with
  cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Configuration 2
AND
   cpe:2.3:a:dtsearch:dtsearch:*:*:*:*:*:*:*:* < 2023.01
  Running on/with
  cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry