The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the WinRAR path traversal vulnerability, CVE-2025-6218, to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. This flaw, which affects Windows-based versions of WinRAR prior to version 7.12, allows attackers to execute arbitrary code by tricking users into opening malicious archives or visiting compromised web pages. The vulnerability enables attackers to write files outside intended directories, potentially leading to code execution with the privileges of the current user, and can be exploited to place files in sensitive locations such as the Windows Startup folder.
Multiple threat groups, including GOFFEE (aka Paper Werewolf), Bitter (aka APT-C-08 or Manlinghua), and Gamaredon, have been observed exploiting CVE-2025-6218 in the wild. Attacks have involved phishing emails containing malicious RAR archives, with some campaigns using the vulnerability to establish persistence and deploy trojans on targeted systems. RARLAB addressed the issue in June 2025 with the release of WinRAR 7.12, and users are urged to update to the latest version to mitigate the risk of exploitation. The vulnerability does not affect WinRAR versions for Unix or Android platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Following the KEV additions, CISA directed Federal Civilian Executive Branch agencies to address both vulnerabilities by December 30, 2025. The agency also urged private-sector organizations to review and remediate the issues.
CISA added CVE-2025-6218 in WinRAR and CVE-2025-62221 in the Microsoft Windows Cloud Files Mini Filter Driver to its Known Exploited Vulnerabilities catalog, citing active exploitation. The Windows flaw is a use-after-free issue that can allow local privilege escalation to SYSTEM.
After the flaw became available for abuse, multiple threat actors including GOFFEE, Bitter, and Gamaredon used CVE-2025-6218 in targeted spear-phishing campaigns. The activity enabled code execution, persistence, and deployment of malware including trojans and wipers, with Gamaredon targeting Ukrainian entities.
In June 2025, RARLAB released WinRAR version 7.12 to fix CVE-2025-6218, a directory traversal/path traversal flaw affecting Windows versions of the software. The bug could allow code execution when a user opens a malicious archive or visits a malicious webpage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.