CVEPublished 2025-08-083 articles on news7 live referencesNVD data

CVE-2025-8088

Vulnerability data via CVEDB (Shodan)

CISA KEVKnown exploited in the wild.
CISA action: RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.
CVSS v3.1
8.4
HIGH
EPSS percentile
94
Exploit Prediction Scoring System · top 6% of all CVEs
Description

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

Timeline
Published 2025-08-08

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub (8)