
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-6218 is a path traversal (directory traversal) vulnerability in RARLAB WinRAR that allows remote attackers to execute arbitrary code on affected systems. The flaw was reported to the vendor on June 5, 2025, and publicly disclosed on June 19, 2025, via the Zero Day Initiative (ZDI-25-409). It affects all WinRAR versions prior to 7.12. The vulnerability carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory, CISA KEV).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal'). The flaw exists within WinRAR's handling of file paths inside archive files: a specially crafted file path embedded in a RAR archive can cause the extraction process to traverse outside the intended target directory, writing files to arbitrary locations on the filesystem — including sensitive directories such as the Windows Startup folder. Exploitation requires user interaction (opening a malicious archive file or visiting a malicious page that triggers extraction), but no privileges are required. Multiple public PoC exploits have been published on GitHub, and detailed technical write-ups are available (ZDI Advisory, SecPod Analysis, Foresiet Blog).
Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, resulting in full compromise of confidentiality, integrity, and availability of the affected system. Attackers have leveraged this vulnerability to drop malware into Windows Startup folders, enabling persistent access and facilitating lateral movement within targeted networks. Confirmed payloads include ROMCOM RAT, Pteranodon, QuasarRAT, and the Infy malware family, with targets spanning government agencies in South Asia, organizations in Russia, and entities in Ukraine (CISA KEV, ESET Research, Bleeping Computer).
CVE-2025-6218 was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on December 9, 2025, with a remediation due date of December 30, 2025, confirming active in-the-wild exploitation (CISA KEV). Multiple threat actors have been attributed to exploitation, including RomCom (Russia-linked), Paper Werewolf/GOFFEE (Russia-linked), Gamaredon Group, APT-C-08 (HAZY TIGER, targeting South Asian governments), and the Iranian Infy APT. Multiple public PoC exploits are available on GitHub, and a zero-day exploit was reportedly listed for sale on dark web forums for $80,000. The EPSS score is approximately 0.65%, though real-world exploitation activity significantly exceeds this estimate (Feedly, Ars Technica, The Record).
..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\malware.exe) to target the Windows Startup folder or another sensitive directory.%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ or %ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup\ following RAR archive extraction; files written outside the user-specified extraction directory by WinRAR.winrar.exe spawning cmd.exe, powershell.exe, or unknown executables); execution of newly dropped binaries from Startup folders shortly after archive extraction.68a5c0b2d0be1fec9ae696fc contains associated IOCs (OTX Pulse).RARLAB has released WinRAR version 7.12 as the patched release addressing CVE-2025-6218; users should update to version 7.12 or later immediately (CISA KEV, ZDI Advisory). CISA's due date for federal agencies to remediate was December 30, 2025. As a workaround prior to patching, users should avoid opening RAR archives from untrusted or unknown sources, and organizations should consider blocking or sandboxing RAR file execution at the email gateway and endpoint level. Monitoring for unexpected file creation in Windows Startup directories is recommended as a compensating control.
ESET Research published a detailed advisory urging users to update WinRAR immediately, noting exploitation by RomCom and other threat actors (ESET Research). Ars Technica reported that the zero-day was exploited for weeks by at least two distinct threat groups before patching (Ars Technica). The Hacker News, Bleeping Computer, The Register, and Tom's Hardware all covered the vulnerability extensively, highlighting the breadth of threat actor involvement. BI.ZONE published a detailed report on Paper Werewolf's exploitation campaign targeting Russian organizations (BI.ZONE). Community reaction on Reddit and security social media was significant, with the vulnerability trending in multiple CVE watch communities and security forums throughout late 2025 and into 2026.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."