The broadly used file compression instrument for Home windows, WinRAR, has simply launched model 7.13 to tackle a extreme safety vulnerability recognized as CVE-2025-8088. This flaw, discovered by ESET security researchers, particularly impacts the Home windows model of WinRAR, concentrating on the UNRAR.dll library. The vulnerability permits attackers to craft malicious archive recordsdata that, when extracted by a person, trick WinRAR into writing recordsdata to a location of the attacker’s selecting as an alternative of the listing chosen by the person.
Exploitation of this vulnerability has been noticed within the wild, notably via phishing campaigns. Attackers have despatched emails containing specifically designed RAR archives that, when extracted, deposit executable recordsdata into delicate Home windows folders such because the Startup folder (%APPDATApercentMicrosoftWindowsStart MenuProgramsStartup). Any bug positioned right here is mechanically executed the subsequent time the system begins, leading to full compromise of the affected machine. This methodology allows attackers to achieve persistent entry and probably execute additional malicious actions, together with putting in distant entry trojans (RATs).
The first malware linked to exploitation of this flaw known as RomCom, a Distant Entry Trojan (RAT) related to cybercriminals identified for social engineering assaults. These attackers disguise their malware as reliable functions, encouraging customers to obtain and set up compromised WinRAR variations. RomCom has been noticed concentrating on organizations in numerous sectors, and there may be proof connecting its exploitation of CVE-2025-8088 to Russian-linked teams. Earlier assaults enabled distant code execution, information exfiltration, and deployment of additional malware payloads.
It is very important observe that Unix variations of RAR and UnRAR, together with the variations for Android, are usually not affected by this vulnerability. The safety concern is confined to Home windows customers, and solely these with the affected variations (previous to 7.13) are in danger.
In contrast to some trendy software program, WinRAR doesn’t characteristic automated updates. Customers should go to the official WinRAR website and manually obtain and set up the newest model to be protected. Failure to improve leaves techniques uncovered to lively threats.
Filed in Security, Windows 10 and Windows 11.
. Learn extra aboutTrending Merchandise

HP 17.3″ FHD Business Laptop 2024, 32GB RAM, 1TB SSD, 12th Gen Intel Core i3-1215U (6-Core, Beat i5-1135G7), Wi-Fi, Long Battery Life, Webcam, Numpad, Windows 11 Pro, KyyWee Accessories

Acer CB272 Ebmiprx 27″ FHD 1920 x 1080 Zero Body Residence Workplace Monitor | AMD FreeSync | 1ms VRB | 100Hz | 99% sRGB | Top Adjustable Stand with Swivel, Tilt & Pivot (Show Port, HDMI & VGA Ports)

Thermaltake Tower 500 Vertical Mid-Tower Pc Chassis Helps E-ATX CA-1X1-00M1WN-00

Wi-fi Keyboard and Mouse Combo, MARVO 2.4G Ergonomic Wi-fi Pc Keyboard with Telephone Pill Holder, Silent Mouse with 6 Button, Appropriate with MacBook, Home windows (Black)

Dell KM3322W Keyboard and Mouse
