Skip to main content
Official Seqrite Distributor in Thailand
Threat researchOriginally published 25 August 2025 · Seqrite Labs

WinRAR flaws: extracting a file is enough — update every PC to 7.13 or later

CVE-2025-6218 and CVE-2025-8088 let a malicious archive write outside the folder you chose — and they've been exploited in the wild.

Seqrite explains two serious WinRAR-for-Windows flaws. Both let a crafted archive write files outside the folder the user picked when extracting — no further click required.

  • CVE-2025-6218 — path traversal in WinRAR 7.11 and earlier, fixed in 7.12 Beta 1.
  • CVE-2025-8088 — abuses NTFS Alternate Data Streams to hide the payload behind a harmless-looking file; affects 7.12 and earlier, fixed in 7.13.
  • Affects the WinRAR GUI and command line, UnRAR and UnRAR.dll.

How it's used

The usual play is to drop an .exe or shortcut into the user's Startup folder so the malware runs at the next logon. Seqrite reports RomCom used CVE-2025-8088 as a zero-day in phishing from mid-July 2025, and expects copycats because it's easy to weaponise.

It's the same pattern as the RAR campaign against Thai hospitals: an archive by email is the way in, and the Startup folder is where it stays.

What a business should do

  • Update WinRAR to 7.13+ on every PC, portable copies included — it doesn't update itself.
  • Remove WinRAR where it isn't needed; Windows opens ZIP natively.
  • Treat archives from email or chat as untrusted — extracting is enough to be infected.
  • Add a Startup-folder check to routine machine health checks.

More news

Evaluate it in your own organisation

30 days, no cost, no commitment. We'll send a trial licence and install steps to the email you give us.

Or call 090-295-5556 · LINE @528gkanm