CVE-2025-6218
WinRAR vulnerability analysis and mitigation

Overview

CVE-2025-6218 is a path traversal (directory traversal) vulnerability in RARLAB WinRAR that allows remote attackers to execute arbitrary code on affected systems. The flaw was reported to the vendor on June 5, 2025, and publicly disclosed on June 19, 2025, via the Zero Day Initiative (ZDI-25-409). It affects all WinRAR versions prior to 7.12. The vulnerability carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory, CISA KEV).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal'). The flaw exists within WinRAR's handling of file paths inside archive files: a specially crafted file path embedded in a RAR archive can cause the extraction process to traverse outside the intended target directory, writing files to arbitrary locations on the filesystem — including sensitive directories such as the Windows Startup folder. Exploitation requires user interaction (opening a malicious archive file or visiting a malicious page that triggers extraction), but no privileges are required. Multiple public PoC exploits have been published on GitHub, and detailed technical write-ups are available (ZDI Advisory, SecPod Analysis, Foresiet Blog).

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, resulting in full compromise of confidentiality, integrity, and availability of the affected system. Attackers have leveraged this vulnerability to drop malware into Windows Startup folders, enabling persistent access and facilitating lateral movement within targeted networks. Confirmed payloads include ROMCOM RAT, Pteranodon, QuasarRAT, and the Infy malware family, with targets spanning government agencies in South Asia, organizations in Russia, and entities in Ukraine (CISA KEV, ESET Research, Bleeping Computer).

Exploitability

CVE-2025-6218 was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on December 9, 2025, with a remediation due date of December 30, 2025, confirming active in-the-wild exploitation (CISA KEV). Multiple threat actors have been attributed to exploitation, including RomCom (Russia-linked), Paper Werewolf/GOFFEE (Russia-linked), Gamaredon Group, APT-C-08 (HAZY TIGER, targeting South Asian governments), and the Iranian Infy APT. Multiple public PoC exploits are available on GitHub, and a zero-day exploit was reportedly listed for sale on dark web forums for $80,000. The EPSS score is approximately 0.65%, though real-world exploitation activity significantly exceeds this estimate (Feedly, Ars Technica, The Record).

Exploitation steps

  1. Craft a malicious RAR archive: The attacker creates a RAR archive containing a file with a crafted path using directory traversal sequences (e.g., ..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\malware.exe) to target the Windows Startup folder or another sensitive directory.
  2. Deliver the archive to the target: The malicious archive is distributed via phishing emails, malicious websites, or other social engineering vectors. Campaigns have used lure documents themed around government orders, military topics, or financial content to entice targets.
  3. Induce user interaction: The target is persuaded to open the malicious RAR file using a vulnerable version of WinRAR (prior to 7.12). No additional privileges are required beyond the user's own context.
  4. Trigger path traversal during extraction: When WinRAR extracts the archive, the crafted file path causes the extraction engine to write the malicious payload outside the intended extraction directory — for example, directly into the Windows Startup folder.
  5. Achieve persistence and code execution: The dropped payload (e.g., ROMCOM RAT, QuasarRAT, Pteranodon) executes automatically on the next system reboot or immediately if the Startup folder is monitored, establishing persistence and enabling further post-exploitation activity such as credential theft, lateral movement, or data exfiltration (ZDI Advisory, SecPod Analysis, Bleeping Computer).

Indicators of compromise

  • File System: Unexpected executable or script files created in %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ or %ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup\ following RAR archive extraction; files written outside the user-specified extraction directory by WinRAR.
  • Process: Unusual child processes spawned by WinRAR (e.g., winrar.exe spawning cmd.exe, powershell.exe, or unknown executables); execution of newly dropped binaries from Startup folders shortly after archive extraction.
  • Network: Outbound connections to unknown or suspicious C2 infrastructure from processes dropped via WinRAR extraction; connections associated with ROMCOM RAT, QuasarRAT, or Pteranodon C2 patterns.
  • Logs: Windows Event Logs showing new file creation events in Startup directories correlated with WinRAR process activity; Sigma rules for WinRAR file creation in Startup folder are available (SigmaHQ).
  • YARA: Public YARA rules for detecting RAR archives with path traversal sequences are available in the Neo23x0 signature-base repository (Neo23x0 YARA).
  • Threat Intelligence: AlienVault OTX pulse 68a5c0b2d0be1fec9ae696fc contains associated IOCs (OTX Pulse).

Mitigation and workarounds

RARLAB has released WinRAR version 7.12 as the patched release addressing CVE-2025-6218; users should update to version 7.12 or later immediately (CISA KEV, ZDI Advisory). CISA's due date for federal agencies to remediate was December 30, 2025. As a workaround prior to patching, users should avoid opening RAR archives from untrusted or unknown sources, and organizations should consider blocking or sandboxing RAR file execution at the email gateway and endpoint level. Monitoring for unexpected file creation in Windows Startup directories is recommended as a compensating control.

Community reactions

ESET Research published a detailed advisory urging users to update WinRAR immediately, noting exploitation by RomCom and other threat actors (ESET Research). Ars Technica reported that the zero-day was exploited for weeks by at least two distinct threat groups before patching (Ars Technica). The Hacker News, Bleeping Computer, The Register, and Tom's Hardware all covered the vulnerability extensively, highlighting the breadth of threat actor involvement. BI.ZONE published a detailed report on Paper Werewolf's exploitation campaign targeting Russian organizations (BI.ZONE). Community reaction on Reddit and security social media was significant, with the vulnerability trending in multiple CVE watch communities and security forums throughout late 2025 and into 2026.

Additional resources


SourceThis report was generated using AI

Related WinRAR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-8088HIGH8.4
  • Clam AntiVirus logoClam AntiVirus
  • cpe:2.3:a:rarlab:winrar
YesYesAug 08, 2025
CVE-2026-14191HIGH7.8
  • WinRAR logoWinRAR
  • cpe:2.3:a:rarlab:winrar
NoYesJul 01, 2026
CVE-2019-25677MEDIUM6.9
  • WinRAR logoWinRAR
  • cpe:2.3:a:rarlab:winrar
NoYesApr 05, 2026
CVE-2025-52331MEDIUM6.1
  • WinRAR logoWinRAR
  • cpe:2.3:a:rarlab:winrar
NoYesNov 12, 2025
CVE-2025-14111LOW1.3
  • WinRAR logoWinRAR
  • rar
NoNoDec 05, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management