The U.S. Cybersecurity and Infrastructure Security Agency ( CISA) reports that the WinRAR vulnerability CVE-2025-8088 is being exploited in ransomware attacks. The vulnerability enables path traversal, allowing a specially crafted archive file to execute code. WinRAR patched the issue last year in version 7.13, but exploitation continues.
Last night, CISA added an update to its list of actively exploited vulnerabilities. It now states that CVE-2025-8088 has also been used in ransomware attacks. Further details about these attacks are not available. The vulnerability had been on the agency’s list since August 12 of last year; the agency tracks separately for each vulnerability whether it is being used in ransomware attacks.
The security vulnerability enables path traversal when extracting archive files. An attacker sends a specially crafted archive to a victim or tricks the victim into downloading it. When the archive is extracted, an executable file is placed, without the user’s knowledge, in a location that Windows automatically loads, such as the Startup folder. After a restart, the system becomes infected.
RomCom behind initial attacks
The European security firm ESET discovered the attacks. According to the researchers, the vulnerability was exploited as a zero-day by the Russia-linked group RomCom, which primarily engages in cyberespionage but also in financial theft. Research shows that the exploit uses directory traversal and Alternate Data Streams to place hidden payloads. According to security researchers, the campaigns targeted organizations in Europe and Canada, including those in the finance, defense, and logistics sectors. ESET’s original publication did not mention ransomware.
Difficult to update
WinRAR fixed the issue on July 24 of last year in the beta version of 7.13; the final release followed on July 30. Exploits were already taking place before the patch was available.
Last June, Trend Micro warned that the exploitation was continuing because WinRAR is difficult to update. The software lacks an automatic update feature, does not support Group Policy, and falls outside the scope of patching systems such as WSUS, SCCM, or Intune. According to Trend Micro, software with these characteristics creates “a permanent blind spot in organizations’ vulnerability management.”
CISA requires federal government agencies to patch vulnerabilities on this list within a specified timeframe.