CVE-2025-6218
Last modified
CVE-2025-6218 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. CISA has confirmed active exploitation in the wild. EPSS estimates a 86.19% chance of exploitation in the next 30 days.
Description
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198.
Metrics
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rarlab | Winrar | < 7.12 |
References
- https://www.zerodayinitiative.com/advisories/ZDI-25-409/Third Party Advisory, VDB Entry
- https://foresiet.com/blog/apt-c-08-winrar-directory-traversal-exploit/Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-6218US Government Resource
- https://www.secpod.com/blog/archive-terror-dissecting-the-winrar-cve-2025-6218-exploit-apt-c-08s-stealth-move/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-6218?
How severe is CVE-2025-6218?
How do I fix CVE-2025-6218?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-62174Mastodon is a free, open-source social network server based …3.5
- CVE-2025-62175Mastodon is a free, open-source social network server based …4.3
- CVE-2025-62176Mastodon is a free, open-source social network server based …4.3
- CVE-2025-62177WeGIA is an open source Web Manager for Institutions with a …8.8
- CVE-2025-62178WeGIA is an open source Web Manager for Institutions with a …5.4
- CVE-2025-62179WeGIA is an open source Web Manager for Institutions with a …8.8
- CVE-2025-62180Pega Platform versions 8.3.0 through Infinity 25.1.2 are aff…7.1
- CVE-2025-62181Pega Platform versions 7.1.0 through Infinity 25.1.0 are aff…5.3
- CVE-2025-62182Pega Customer Service Framework versions 8.7.0 through 25.1.…5.3
- CVE-2025-62183Pega Platform versions 8.1.0 through 25.1.1 are affected by …4.8
- CVE-2025-62184Pega Platform versions 8.1.0 through 25.1.0 are affected by …3.4
- CVE-2025-62185In Ankitects Anki before 25.02.5, a crafted shared deck can …7.8
Are you affected by CVE-2025-6218?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
