The extensively used file compression software for Home windows, WinRAR, has simply launched model 7.13 to deal with a extreme safety vulnerability recognized as CVE-2025-8088. This flaw, discovered by ESET security researchers, particularly impacts the Home windows model of WinRAR, focusing on the UNRAR.dll library. The vulnerability permits attackers to craft malicious archive information that, when extracted by a person, trick WinRAR into writing information to a location of the attacker’s selecting as an alternative of the listing chosen by the person.
Exploitation of this vulnerability has been noticed within the wild, notably by means of phishing campaigns. Attackers have despatched emails containing specifically designed RAR archives that, when extracted, deposit executable information into delicate Home windows folders such because the Startup folder (%APPDATApercentMicrosoftWindowsStart MenuProgramsStartup). Any computer virus positioned right here is mechanically executed the following time the system begins, leading to full compromise of the affected machine. This technique allows attackers to achieve persistent entry and doubtlessly execute additional malicious actions, together with putting in distant entry trojans (RATs).
The first malware linked to exploitation of this flaw is named RomCom, a Distant Entry Trojan (RAT) related to cybercriminals recognized for social engineering assaults. These attackers disguise their malware as authentic purposes, encouraging customers to obtain and set up compromised WinRAR variations. RomCom has been noticed focusing on organizations in numerous sectors, and there’s proof connecting its exploitation of CVE-2025-8088 to Russian-linked teams. Earlier assaults enabled distant code execution, information exfiltration, and deployment of additional malware payloads.
It is very important notice that Unix variations of RAR and UnRAR, together with the variations for Android, will not be affected by this vulnerability. The safety subject is confined to Home windows customers, and solely these with the affected variations (previous to 7.13) are in danger.
Not like some trendy software program, WinRAR doesn’t function automated updates. Customers should go to the official WinRAR website and manually obtain and set up the newest model to be protected. Failure to improve leaves methods uncovered to lively threats.
Filed in . Learn extra about Security, Windows 10 and Windows 11.
Trending Merchandise
MSI MAG Forge 112R – Premium Mid-Tower Gaming PC Case – Tempered Glass Side Panel – ARGB 120mm Fans – Liquid Cooling Support up to 240mm Radiator – Vented Front Panel
HP 15.6″ Touchscreen Laptop, Intel Core i3-1215U Processor, 32GB RAM, 1TB SSD, Numeric Keypad, Bluetooth, Wi-Fi, Long Battery Life, SD Card Reader, Windows 11 Home, Alpacatec Accessories, Silver
NZXT H5 Stream Compact ATX Mid-Tower PC Gaming Case – Excessive Airflow Perforated Tempered Glass Entrance/Aspect Panel – Cable Administration – 2 x 120mm Followers Included – 280mm Radiator Help – Black
ASUS 15.6â Vivobook Go Slim Laptop, Intel Dual Core N4500, 4GB RAM, 128GB SSD, Windows 11, Star Black, L510KA-ES04
15.6” Laptop computer 12GB DDR4 512GB SSD, Quad-Core Intel Celeron N5095 Processors, Home windows 11 1080P IPS FHD Show Laptop computer Laptop,Numeric Keypad USB 3.0, Bluetooth 4.2, 2.4/5G WiFi
HP Latest 14″ Ultral Gentle Laptop computer for College students and Enterprise, Intel Quad-Core N4120, 8GB RAM, 192GB Storage(64GB eMMC+128GB Micro SD), 1 Yr Workplace 365, Webcam, HDMI, WiFi, USB-A&C, Win 11 S
Lenovo IdeaPad 1 14 Laptop computer, 14.0″ HD Show, Intel Celeron N4020, 4GB RAM, 64GB Storage, Intel UHD Graphics 600, Win 11 in S Mode, Cloud Gray
Gaming Keyboard and Mouse Combo, K1 RGB LED Backlit Keyboard with 104 Key for PC/Laptop(White)
LG 27MP400-B 27 Inch Monitor Full HD (1920 x 1080) IPS Display with 3-Side Virtually Borderless Design, AMD FreeSync and OnScreen Control â Black
