CISA Warns About New WinRAR Zero Day RCE Vulnerability
Could a simple RAR file, something as ordinary as a job application or resume, give attackers full access to your Windows computer? In 2025, that frightening scenario became reality.
In July to August 2025, security researchers uncovered critical zero-day vulnerabilities in WinRAR, one of the world’s most widely used file compression tools. These flaws allowed attackers to execute malicious code simply by tricking users into extracting a specially crafted archive.
Government agencies, cybersecurity firms, and enterprises issued urgent advisories worldwide. The message was clear:
If you use WinRAR on Windows and haven’t updated to version 7.13, you are at risk.
This article breaks down how the exploit works, why it’s so dangerous, and what individuals and organizations must do now.
CVE-2025-8088 and CVE-2025-6218
The root cause lies in how certain Windows versions of WinRAR handled:
Directory (path) traversal NTFS Alternate Data Streams (ADS)
These issues, tracked as CVE-2025-8088 and CVE-2025-6218, allowed attackers to override the extraction path chosen by the user. Instead of placing extracted files in a safe folder, WinRAR could be tricked into silently dropping files into:
Windows Startup folders System directories Other auto-run locations
This meant that simply extracting an archive could automatically execute malware on the system boot without any further user interaction.
July 18, 2025: Security researchers detected suspicious file paths inside a malicious RAR archive containing a weaponized msedge.dll. July 24, 2025: WinRAR developers were notified. July 30, 2025: WinRAR 7.13 was released with a security patch. The earlier related flaw CVE-2025-6218 further increased the severity by enabling additional traversal abuse.
Because WinRAR is still massively used across enterprises and personal devices, the exposure was global and immediate.
1. Weaponized Archive Creation Attackers created RAR files that appeared harmless such as resumes, invoices, and job applications. These files embedded malware using:
Relative path traversal (..) NTFS alternate data streams for hidden payloads
2. Phishing Delivery Victims received spear-phishing emails designed to look legitimate and urgent.
3. Malicious Extraction With vulnerable WinRAR versions 7.12 or earlier, hidden files were silently extracted into Windows startup and system folders.
4. Automatic Execution On the login or reboot, the malware executed automatically.
5. Full System Compromise Attackers installed backdoors, spyware, remote access tools, and escalated privileges for deeper network access.
A trusted everyday tool became a stealth malware delivery system.
This was not a theoretical vulnerability. It was actively exploited in the wild.
Threat intelligence reports linked real-world attacks to:
RomCom Paper Werewolf
These groups targeted businesses using realistic phishing lures such as:
Job applications Legal documents Business proposals
What made this attack especially dangerous:
Massive global WinRAR user base Manual update process with no forced auto-update Hidden payloads via NTFS ADS Social engineering combined with technical exploitation
For HR teams, finance departments, and admin staff who regularly open attachments, this was a perfect storm.
An HR officer receives an email titled Candidate Application – Jane Smith
Attachment: JaneSmith_Resume.rar
She extracts it using an outdated WinRAR version. What she does not see:
A hidden malicious DLL A shortcut planted in the Windows Startup folder
No alerts. No warnings.
The morning, the system boots and the attacker now has remote access to the company network. Data theft begins. Backdoors are installed. All from a single resume.
This is exactly the type of campaign attributed to RomCom in 2025.
It turned a trusted utility into a malware delivery weapon Attackers could override user-selected extraction paths Hidden NTFS payloads are extremely hard to detect No obvious signs of compromise during extraction
Even mature, widely trusted software requires constant patching Manual update models increase exposure windows Attackers now routinely combine social engineering with subtle technical flaws
Security is no longer just a technical problem. It is a human behavior and process problem.
Immediately update WinRAR to version 7.13 or later Treat unexpected RAR or ZIP attachments with extreme caution Use endpoint detection tools to monitor: For organizations:
What is the WinRAR zero-day vulnerability? A flaw in WinRAR for Windows up to version 7.12 that allows attackers to extract malware into system and startup folders using path traversal and alternate data streams. Tracked as CVE-2025-8088 and CVE-2025-6218.
Was it officially confirmed? Yes. Security vendors and WinRAR confirmed active exploitation. The patch was released on July 30, 2025 with version 7.13.
How does it enable remote code execution? By planting executable files into auto-run directories during extraction, which run automatically on reboot.
How can I stay protected? Update WinRAR immediately, avoid unsolicited archives, deploy endpoint protection, and train staff on phishing risks.
The WinRAR zero-day of 2025 is a powerful reminder that cyber risk often hides inside the most ordinary tools we trust every day. CVE-2025-8088 and CVE-2025-6218 showed how a simple archive file could become a gateway for global cyber-espionage.
Updating to WinRAR 7.13 is critical, but true protection goes beyond patching. It requires strong email security, continuous endpoint monitoring, and a culture of cybersecurity awareness.
Because in today’s threat landscape, even a resume can be a weapon.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
