← Browse

CVE-2025-8088

Act now ● On CISA KEV — actively exploited used in ransomware

Actively exploited — on the CISA KEV list.

CVSS base
8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
94.1%
99.8th percentile
CISA KEV
Listed
Added 2025-08-12 · patch by 2025-09-02
Weakness / dates
CWE-35
Published 2025-08-08 · modified 2026-08-11

Description

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

Affected

dtsearch microsoft rarlab

References

Official: NVD · CVE.org