The extensively used file compression device for Home windows, WinRAR, has simply launched model 7.13 to deal with a extreme safety vulnerability recognized as CVE-2025-8088. This flaw, discovered by ESET security researchers, particularly impacts the Home windows model of WinRAR, concentrating on the UNRAR.dll library. The vulnerability permits attackers to craft malicious archive information that, when extracted by a consumer, trick WinRAR into writing information to a location of the attacker’s selecting as a substitute of the listing chosen by the consumer.
Exploitation of this vulnerability has been noticed within the wild, notably via phishing campaigns. Attackers have despatched emails containing specifically designed RAR archives that, when extracted, deposit executable information into delicate Home windows folders such because the Startup folder (%APPDATApercentMicrosoftWindowsStart MenuProgramsStartup). Any bug positioned right here is routinely executed the subsequent time the system begins, leading to full compromise of the affected machine. This methodology allows attackers to realize persistent entry and doubtlessly execute additional malicious actions, together with putting in distant entry trojans (RATs).
The first malware linked to exploitation of this flaw known as RomCom, a Distant Entry Trojan (RAT) related to cybercriminals recognized for social engineering assaults. These attackers disguise their malware as reputable functions, encouraging customers to obtain and set up compromised WinRAR variations. RomCom has been noticed concentrating on organizations in numerous sectors, and there may be proof connecting its exploitation of CVE-2025-8088 to Russian-linked teams. Earlier assaults enabled distant code execution, information exfiltration, and deployment of additional malware payloads.
It is very important word that Unix variations of RAR and UnRAR, together with the variations for Android, should not affected by this vulnerability. The safety problem is confined to Home windows customers, and solely these with the affected variations (previous to 7.13) are in danger.
In contrast to some fashionable software program, WinRAR doesn’t function computerized updates. Customers should go to the official WinRAR website and manually obtain and set up the most recent model to be protected. Failure to improve leaves techniques uncovered to energetic threats.
Filed in Security, Windows 10 and Windows 11.
. Learn extra aboutTrending Merchandise

Dell Inspiron 15 3000 3520 Enterpri...

HP 27h Full HD Monitor – Diag...

LG UltraWide QHD 34-Inch Pc Monitor...

Acer Nitro 27″ WQHD 2560 x 14...

TP-Link AX5400 WiFi 6 Router (Arche...

Laptop computer Pc, 15.6 Inch FHD S...

ASUS VA24DQ 23.8” Monitor, 1080P ...
