CVE-2025-6218 Details
Description
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198.
A directory traversal vulnerability allowing remote code execution has been identified in RARLAB WinRAR. This issue arises from improper handling of file paths within archive files, enabling an attacker to craft a file path that traverses to unintended directories. Exploitation requires user interaction, as the target must open a malicious file or visit a harmful webpage. The vulnerability affects WinRAR versions prior to 7.11.
RARLAB has released a patch for this vulnerability in WinRAR version 7.11. Users are advised to update to this version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://foresiet.com/blog/apt-c-08-winrar-directory-traversal-exploit/ | CISA-ADP | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-6218 | CISA-ADP | US Government Resource |
| https://www.secpod.com/blog/archive-terror-dissecting-the-winrar-cve-2025-6218-exploit-apt-c-08s-stealth-move/ | CISA-ADP | ExploitThird Party Advisory |
| https://www.win-rar.com/singlenewsview.html?&tx_ttnews%5Btt_news%5D=276&cHash=388885bd3908a40726f535c026f94eb6 | [email protected] | Release Notes |
| https://www.zerodayinitiative.com/advisories/ZDI-25-409/ | [email protected] | Third Party AdvisoryVDB Entry |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| RARLAB WinRAR Path Traversal Vulnerability | Dec 9, 2025 | Dec 30, 2025 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rarlab winrar | < 7.12 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 10, 2025 | Modified Analysis | [email protected] |
| Dec 9, 2025 | CVE Modified | CISA-ADP |
| Jun 25, 2025 | Initial Analysis | [email protected] |
| Jun 21, 2025 | New CVE Received | [email protected] |