目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-8088— WinRAR 安全漏洞

一分钟漏洞结论

影响对象
win.rar GmbH WinRAR
利用判断
已确认在野利用,应立即处置
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

WinRAR是WinRAR公司的一款文件压缩器。该产品支持RAR、ZIP等格式文件的压缩和解压等。 WinRAR存在安全漏洞,该漏洞源于路径遍历问题,可能导致任意代码执行。

CVSS 8.4 · High KEV · 勒索软件 EPSS 94.05% · P100

影响版本矩阵 1

厂商产品 版本范围状态
win.rar GmbH WinRAR ≤ 7.12 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2025-8088 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Path traversal vulnerability in WinRAR
来源: CVE Program / CVE List V5
Vulnerability Description
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
路径遍历:’…/…//’
来源: CVE Program / CVE List V5
Vulnerability Title
WinRAR 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
WinRAR是WinRAR公司的一款文件压缩器。该产品支持RAR、ZIP等格式文件的压缩和解压等。 WinRAR存在安全漏洞,该漏洞源于路径遍历问题,可能导致任意代码执行。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
win.rar GmbH WinRAR 0 ~ 7.12 -

二、漏洞 CVE-2025-8088 的公开POC

# POC 描述 源链接 神龙链接
1 Python tool for safe archive handling, path traversal awareness, and secure extraction. Inspired by CVE-2025-8088. https://github.com/jordan922/CVE-2025-8088 POC详情
2 cve-2025-8088_detection https://github.com/travisbgreen/cve-2025-8088 POC详情
3 WinRAR 0day CVE-2025-8088 PoC RAR Archive https://github.com/knight0x07/WinRAR-CVE-2025-8088-PoC-RAR POC详情
4 CVE-2025-8088 WinRAR Proof of Concept (PoC-Exploit) https://github.com/sxyrxyy/CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit- POC详情
5 Advanced WinRAR Path Traversal Exploit Tool for CVE-2025-8088 https://github.com/onlytoxi/CVE-2025-8088-Winrar-Tool POC详情
6 None https://github.com/0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC POC详情
7 Exploit systems using older WinRAR https://github.com/pentestfunctions/CVE-2025-8088-Multi-Document POC详情
8 Proof-of-Concept for CVE-2025-8088 vulnerability in WinRAR (path traversal via ADS) https://github.com/pexlexity/WinRAR-CVE-2025-8088-Path-Traversal-PoC POC详情
9 None https://github.com/Syrins/CVE-2025-8088-Winrar-Tool-Gui POC详情
10 🚀 Demonstrate the WinRAR CVE-2025-8088 exploit with a PoC RAR archive that installs a VBScript on startup, showcasing its impact on vulnerable systems. https://github.com/amel-62/WinRAR-CVE-2025-8088-PoC-RAR POC详情
11 This PoC is for authorized study and testing. CVE-2025-8088 is actively exploited, and misuse may violate laws or cause harm. Update to WinRAR 7.13+ to avoid suspicious RARs. https://github.com/ghostn4444/CVE-2025-8088 POC详情
12 None https://github.com/DeepBlue-dot/CVE-2025-8088-WinRAR-Startup-PoC POC详情
13 POWERSHEL script to check if your device is affected or no https://github.com/pescada-dev/-CVE-2025-8088 POC详情
14 An engaging walkthrough on uncovering, patching, and securing the WinRAR CVE-2025-8088 with a hands-on hacker’s twist. https://github.com/AdityaBhatt3010/CVE-2025-8088-WinRAR-Zero-Day-Path-Traversal POC详情
15 Winrar CVE exploitation before 7.13 using multiple ADS streams on a single file (Custom PDF implementation) https://github.com/pentestfunctions/best-CVE-2025-8088 POC详情
16 None https://github.com/nyra-workspace/CVE-2025-8088 POC详情
17 A high-performance, memory-safe implementation of the WinRAR CVE-2025-8088 exploit tool, rewritten in Rust for better reliability and performance. https://github.com/kitsuneshade/WinRAR-Exploit-Tool---Rust-Edition POC详情
18 None https://github.com/walidpyh/CVE-2025-8088 POC详情
19 None https://github.com/hexsecteam/CVE-2025-8088-Winrar-Tool POC详情
20 WinRAR CVE-2025-8088 exploit tool https://github.com/cozythrill/CVE-2025-8088 POC详情
21 CVE-2025-8088 path traversal tool https://github.com/tartalu/CVE-2025-8088 POC详情
22 A proof-of-concept exploit for WinRAR vulnerability (CVE-2025-8088) affecting versions 7.12 and lower. This tool creates a malicious RAR archive that embeds payloads in Alternate Data Streams (ADS) with path traversal, potentially leading to arbitrary code execution. https://github.com/techcorp/CVE-2025-8088-Exploit POC详情
23 CVE-2025-8088 https://github.com/nhattanhh/CVE-2025-8088 POC详情
24 None https://github.com/Shinkirou789/Cve-2025-8088-WinRar-vulnerability POC详情
25 WinRAR漏洞CVE-2025-8088的payload一键生成工具 https://github.com/hbesljx/CVE-2025-8088-EXP POC详情
26 CVE-2025-8088 path traversal tool https://github.com/Osinskitito499/CVE-2025-8088 POC详情
27 CVE-2025-8088 path traversal tool https://github.com/m4nbun/CVE-2025-8088 POC详情
28 🚨 Exploit WinRAR CVE-2025-8088 with this PoC RAR archive, demonstrating the vulnerability and its impact when executed on the affected software. https://github.com/pablo388/WinRAR-CVE-2025-8088-PoC-RAR POC详情
29 CVE-2025-8088 exploit C++ impl https://github.com/lucyna77/winrar-exploit POC详情
30 CVE-2025-8088 based path traversal tool https://github.com/kyomber/CVE-2025-8088 POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-8088 的情报信息

请登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-8088

暂无评论


发表评论