Skip to content
Path Traversal and RCE Vulnerabilities in WinRAR Exploited

Path Traversal and RCE Vulnerabilities in WinRAR Exploited

First seen 29 Sep 2026, 13:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 13:11 UTC
  • •CVE-2025-8088 allows path traversal in WinRAR, enabling malicious file placement.
  • •CVE-2023-38831 exploits benign files to execute malware in older WinRAR versions.
  • •Both vulnerabilities are actively exploited, with patches available for affected versions.

Two critical vulnerabilities in WinRAR have been reported: CVE-2025-8088, a path traversal flaw affecting versions up to 7.12, and CVE-2023-38831, a remote code execution vulnerability in versions prior to 6.23. CVE-2025-8088 allows attackers to exploit alternate data streams in crafted RAR files, leading to the execution of malicious files upon system reboot. This vulnerability has been linked to the Russia-aligned RomCom group, which has targeted sectors including finance and defense since July 2025. CVE-2023-38831 enables malware execution when a benign file is opened, affecting users of older WinRAR versions. Both vulnerabilities have been exploited in the wild, with CVE-2025-8088 confirmed in attacks since mid-2025. Patches for these vulnerabilities have been released, with CVE-2025-8088 fixed in version 7.13 on July 30, 2025, and CVE-2023-38831 addressed in version 6.23. Users are urged to update their WinRAR installations to mitigate these risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2023-08-23
CVE-2023-38831 published
Remote code execution vulnerability disclosed, affecting WinRAR versions prior to 6.23.
Sploitus
2023-08-24
CVE-2023-38831 added to CISA KEV
CISA includes CVE-2023-38831 in its Known Exploited Vulnerabilities catalog.
Sploitus
2023-08-25
First public PoC for CVE-2023-38831
Proof-of-concept code for the remote code execution vulnerability made public.
Sploitus
2025-07-18
Exploitation of CVE-2025-8088 begins
Exploitation in the wild confirmed, targeting finance and defense sectors.
Sploitus
2025-07-30
Patch for CVE-2025-8088 released
WinRAR version 7.13 released to fix the path traversal vulnerability.
Sploitus

More articles in this cluster (2)

Following this threat?

Track RomCom and CVE-2023-38831 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed