CVE-2025-8088

Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 13 articles Published: 2025-08-08

EPSS Score

Source: FIRST.org · 2026-05-24
8.34%
probability
This CVE has a 8.34% probability of being exploited in the next 30 days.
0% Top 92.4th percentile of all CVEs 100%

CVSS v4.0 NEW

Source: VulnerabilityLookup (CIRCL)
8.4
HIGH
Attack Vector
Local
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
Active
Vulnerable System Confidentiality Impact
High
Vulnerable System Integrity Impact
High
Vulnerable System Availability Impact
High
Subsequent System Confidentiality Impact
None
Subsequent System Integrity Impact
None
Subsequent System Availability Impact
None
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

VulnerabilityLookup (CNA)
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

Affected Products

win.rar GmbH
WinRAR
0

Attack Intelligence

Exploits & PoC

sxyrxyy/CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit-

CVE-2025-8088 WinRAR Proof of Concept (PoC-Exploit)

69
onlytoxi/CVE-2025-8088-Winrar-Tool

Advanced WinRAR Path Traversal Exploit Tool for CVE-2025-8088

55
pentestfunctions/CVE-2025-8088-Multi-Document

Exploit systems using older WinRAR without knowing their username (unlike other projects)

35
hexsecteam/CVE-2025-8088-Winrar-Tool

A sophisticated GUI tool for creating malicious RAR archives that exploit the WinRAR path traversal vulnerability (CVE-2025-8088) using ADS and RAR5 h

29
jordan922/CVE-2025-8088

Python tool for safe archive handling, path traversal awareness, and secure extraction. Inspired by CVE-2025-8088.

10
pentestfunctions/best-CVE-2025-8088

Winrar CVE exploitation before 7.13 using multiple ADS streams on a single file (Custom PDF implementation)

10
7 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
95%
EPSS 8.34%
CVSS v4.0 8.4
Mentions 13
Last Seen Jun 09, 2026

CNA Information

CNA Assigner
ESET
CNA Title
Path traversal vulnerability in WinRAR

Analyst Note

CVE-2025-8088 is explicitly named as a zero-day in authoritative sources (BleepingComputer, TheHackerNews), with clear evidence of exploitation in the wild by multiple threat actors including nation-state adversaries. The CVE was discovered and patched in July 2025, with exploitation occurring during or immediately after patch availability, meeting the zero-day criteria.

Threat Actors 47

MuddyWater
apt_group Information theft and espionage 🇮🇷 IR
Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
APT 41
apt_group Information theft and espionage 🇨🇳 CN
APT 29
apt_group Information theft and espionage 🇷🇺 RU
Mustang Panda
apt_group Information theft and espionage 🇨🇳 CN
APT37
apt_group Information theft and espionage 🇰🇵 KP
APT 28
apt_group Information theft and espionage 🇷🇺 RU
SparklingGoblin
apt_group Information theft and espionage 🇨🇳 CN
Hacking Team
apt_group 🇮🇹 IT
GhostEmperor
apt_group Information theft and espionage 🇨🇳 CN
SCATTERED SPIDER
apt_group Financial crime 🇺🇸 US
Gamaredon Group
apt_group Information theft and espionage 🇷🇺 RU
HAZY TIGER
apt_group Information theft and espionage 🇮🇳 IN
ELECTRUM
apt_group Information theft and espionage 🇷🇺 RU
Infy
apt_group Information theft and espionage 🇮🇷 IR
UNC6040
apt_group Unknown
Camaro Dragon
apt_group Information theft and espionage 🇨🇳 CN
SideWinder
apt_group 🇮🇳 IN
RAZOR TIGER
apt_group Information theft and espionage 🇮🇳 IN
[Unnamed group]
apt_group 🇨🇳 CN
FamousSparrow
apt_group Information theft and espionage 🇨🇳 CN
RomCom
apt_group Financial gain 🇷🇺 RU
Opal Sleet
apt_group 🇰🇵 KP
Earth Estries
apt_group Information theft and espionage 🇨🇳 CN
Twisted Panda
apt_group Information theft and espionage 🇨🇳 CN
SNOWGLOBE
apt_group Information theft and espionage 🇫🇷 FR
Returned Libra
apt_group 🇨🇳 CN
APT-C-27
apt_group Information theft and espionage 🇸🇾 SY
APT 22
apt_group Information theft and espionage 🇨🇳 CN
RedGolf
apt_group Information theft and espionage 🇨🇳 CN
Rocke
apt_group 🇨🇳 CN
Void Rabisu
apt_group Financial gain 🇷🇺 RU
APT 6
apt_group Information theft and espionage 🇨🇳 CN
UAC-0184
apt_group 🇺🇦 UA
GOFFEE
apt_group 🇷🇺 RU
PKPLUG
apt_group Information theft and espionage 🇨🇳 CN
Water Bakunawa
apt_group 🇷🇺 RU
Bitwise Spider
apt_group Financial gain 🇷🇺 RU
Red October
apt_group 🇷🇺 RU
Circles
apt_group Global
Pat Bear
apt_group 🇸🇾 SY
Unnamed Actor
apt_group 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Poisonous Panda
apt_group Information theft and espionage 🇨🇳 CN
MONTY SPIDER
apt_group Financial crime 🇺🇸 US
APT 5
apt_group Information theft and espionage 🇨🇳 CN
UAC-0099
apt_group 🇺🇦 UA

Triage Info

Decided atMar 05, 2026
Published DateAug 08, 2025