{"cve":{"cve_id":"CVE-2025-8088","is_kev":true,"kev_date_added":"2025-08-12","kev_vendor_project":"RARLAB","kev_product":"WinRAR","kev_vulnerability_name":"RARLAB WinRAR Path Traversal Vulnerability","kev_short_description":"RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.","kev_required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","kev_due_date":"2025-09-02","kev_known_ransomware":true,"kev_notes":"https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=283&cHash=a64b4a8f662d3639dec8d65f47bc93c5 ; https://nvd.nist.gov/vuln/detail/CVE-2025-8088","kev_cwes":["CWE-35"],"epss_score":0.94551,"epss_percentile":0.99847,"epss_as_of":"2026-08-26","description":"A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček\n     from ESET.","published_at":"2025-08-08T11:11:41.842000Z","last_modified_at":"2026-08-11T04:17:18.587000Z","cvss_v3_score":8.8,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cvss_v3_severity":"HIGH","cvss_v4_score":8.4,"cvss_v4_vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cvss_v4_severity":"HIGH","ssvc_decision":null,"ssvc_exploitation":"active","ssvc_automatable":false,"ssvc_technical_impact":"total","cwes":["CWE-35"],"nvd_references":["https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=283&cHash=a64b4a8f662d3639dec8d65f47bc93c5"],"vuln_status":"Analyzed","trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:31.350578Z","updated_at":"2026-08-13T20:20:23.063882Z"},"effective_severity":"HIGH","badges":["kev","ransomware","news","epss"],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"R","value_label":"Required"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"H","value_label":"High"},{"metric":"A","name":"Availability","value":"H","value_label":"High"}]},"cvss_v4_decoded":{"version":"4.0","metrics":[{"metric":"AV","name":"Attack Vector","value":"L","value_label":"Local"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"AT","name":"Attack Requirements","value":"N","value_label":"None"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"A","value_label":"Active"},{"metric":"VC","name":"Confidentiality (Vulnerable System)","value":"H","value_label":"High"},{"metric":"VI","name":"Integrity (Vulnerable System)","value":"H","value_label":"High"},{"metric":"VA","name":"Availability (Vulnerable System)","value":"H","value_label":"High"},{"metric":"SC","name":"Confidentiality (Subsequent System)","value":"N","value_label":"None"},{"metric":"SI","name":"Integrity (Subsequent System)","value":"N","value_label":"None"},{"metric":"SA","name":"Availability (Subsequent System)","value":"N","value_label":"None"}]},"affected":[{"vendor_slug":"dtsearch","vendor_name":"dtsearch","product_slug":"dtsearch","product_name":"dtsearch","version_start":null,"version_start_inclusive":null,"version_end":"2023.01","version_end_inclusive":false,"cpe23_uri":"cpe:2.3:a:dtsearch:dtsearch:*:*:*:*:*:*:*:*"},{"vendor_slug":"rarlab","vendor_name":"RARLAB","product_slug":"winrar","product_name":"WinRAR","version_start":null,"version_start_inclusive":null,"version_end":"7.13","version_end_inclusive":false,"cpe23_uri":"cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:*"},{"vendor_slug":"win.rar-gmbh","vendor_name":"win.rar GmbH","product_slug":"winrar","product_name":"WinRAR","version_start":"0","version_start_inclusive":true,"version_end":"7.12","version_end_inclusive":true,"cpe23_uri":"cve5:win.rar-gmbh:winrar:0:7.12"}],"exploit_refs":[],"news":[{"id":108,"source":"Dark Reading","url":"https://www.darkreading.com/vulnerabilities-threats/russian-groups-winrar-flaw-ukrainian-orgs","title":"Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs","summary":"Two separate campaigns target CVE-2025-8088, fixed last July, to conduct data theft and cyberespionage against military and government targets in Ukraine.","thumbnail_url":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt0de7e1fa7b975bb4/6a2830dd09a01a8cc3ee406e/bug-sankai-Getty-2192972249.jpg?width=720&quality=80&disable=upscale","author":"Elizabeth Montalbano","published_at":"2026-06-09T15:37:02Z","fetched_at":"2026-06-24T00:09:36.117839Z","trending_score":1.4872855693620111e-12,"cve_ids":["CVE-2025-8088"]}],"references":[{"url":"https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=283&cHash=a64b4a8f662d3639dec8d65f47bc93c5","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2025-08-08T11:11:41.842000Z","label":"CVE published","source":null},{"type":"cisa_reported","at":"2025-08-12T00:00:00Z","label":"Added to CISA KEV catalog","source":"kev"},{"type":"first_article","at":"2026-06-09T15:37:02Z","label":"First news coverage","source":"Dark Reading"},{"type":"cvss_changed","at":"2026-06-28T17:49:56.134173Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:49:56.134173Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:49:56.134173Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"ssvc_changed","at":"2026-06-29T23:46:59.033383Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T23:46:59.033383Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T23:46:59.033383Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-08-13T20:20:23.063882Z","label":"CVSS score revised","source":"nvd"},{"type":"cvss_changed","at":"2026-08-13T20:20:23.063882Z","label":"CVSS score revised","source":"nvd"},{"type":"cvss_changed","at":"2026-08-13T20:20:23.063882Z","label":"CVSS score revised","source":"nvd"}]}