Sploitus Path Traversal and RCE Vulnerabilities in WinRAR Exploited
Article Content
- •CVE-2025-8088 allows path traversal in WinRAR, enabling malicious file placement.
- •CVE-2023-38831 exploits benign files to execute malware in older WinRAR versions.
- •Both vulnerabilities are actively exploited, with patches available for affected versions.
Two critical vulnerabilities in WinRAR have been reported: CVE-2025-8088, a path traversal flaw affecting versions up to 7.12, and CVE-2023-38831, a remote code execution vulnerability in versions prior to 6.23. CVE-2025-8088 allows attackers to exploit alternate data streams in crafted RAR files, leading to the execution of malicious files upon system reboot. This vulnerability has been linked to the Russia-aligned RomCom group, which has targeted sectors including finance and defense since July 2025. CVE-2023-38831 enables malware execution when a benign file is opened, affecting users of older WinRAR versions. Both vulnerabilities have been exploited in the wild, with CVE-2025-8088 confirmed in attacks since mid-2025. Patches for these vulnerabilities have been released, with CVE-2025-8088 fixed in version 7.13 on July 30, 2025, and CVE-2023-38831 addressed in version 6.23. Users are urged to update their WinRAR installations to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track RomCom and CVE-2023-38831 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
DarkMe RAT Campaign Shifts to Phishing Tactics The DarkMe remote access trojan (RAT), previously associated with the Water Hydra threat group, has shifted its distribution method from exploiting zero-day vulnerabilities to using phishing emails. Victims receive emails containing links that appear to lead to image files but instead download a malicious executable…
DarkMe RAT Evolves: From Exploits to Social Engineering Attacks The DarkMe malware, a Visual Basic 6 (VB6) remote access trojan (RAT), was identified in two incidents affecting different organizations on August 31, 2026. Previously attributed to the APT group Evilnum, DarkMe has transitioned from using zero-day exploits (CVE-2023-38831 and CVE-2024-21412) to relying on social…