WinRAR developers released version 7.13 to fix CVE-2025-8088, a severe directory traversal vulnerability in WinRAR for Windows and UnRAR for Windows that was reportedly exploited in the wild. The flaw allowed specially crafted archives to extract files outside the intended destination, including into the Windows Startup folder, enabling malware to launch automatically on the next system boot. Affected software included WinRAR versions prior to 7.13 and UnRAR 7.0 for Windows.
According to CSIRT.SK, the vulnerability was used frequently in phishing campaigns to deliver malware, increasing the risk to enterprise users who open archive attachments from untrusted sources. The issue was discovered by ESET researchers Anton Cherepanov, Peter Košinár, and Peter Strýček, and defenders were urged to update immediately and inspect Startup folder contents for suspicious files or shortcuts that may indicate compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
ESET researchers Anton Cherepanov, Peter Košinár, and Peter Strýček discovered CVE-2025-8088, the WinRAR and UnRAR for Windows vulnerability later fixed in version 7.13. The referenced content attributes the discovery to these researchers but does not provide a specific date for it.
WinRAR developers released version 7.13 to fix CVE-2025-8088, a directory traversal vulnerability affecting WinRAR for Windows and UnRAR for Windows. The flaw had been actively exploited in phishing campaigns to place malicious files in the Windows Startup folder for execution on reboot.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.