目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-8088 PoC — WinRAR 安全漏洞

来源
关联漏洞
标题: WinRAR 安全漏洞 (CVE-2025-8088)
Description:WinRAR是WinRAR公司的一款文件压缩器。该产品支持RAR、ZIP等格式文件的压缩和解压等。 WinRAR存在安全漏洞,该漏洞源于路径遍历问题,可能导致任意代码执行。
介绍
# CVE-2025-8088 WinRAR Path Traversal Exploit (PoC)

![PoC Demo](https://github.com/0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC/blob/main/scr.png)

A Proof-of-Concept exploit demonstrating the WinRAR path traversal vulnerability **(CVE-2025-8088)** affecting versions ≤ 7.12.

---

## Vulnerability Details

**CVE ID**: CVE-2025-8088  
**CVSS Score**: 8.4 (High)  
**Affected Versions**: WinRAR ≤ 7.12  
**Patch Version**: Fixed in WinRAR 7.13  
**Vulnerability Type**: Path Traversal via Alternate Data Streams (ADS)

## Overview of CVE-2025-8088

**CVE-2025-8088** is a path traversal vulnerability in WinRAR, affecting Windows versions up to **7.12**, as well as related tools like **UnRAR.dll** and its portable source code.  
The flaw allows attackers to embed malicious payloads in **ADSes** within specially crafted RAR files, enabling extraction to sensitive system locations (e.g., the Windows Startup folder).  
This can lead to automatic execution of malicious files, such as **DLLs** or shortcut (`.lnk`) files, upon system reboot.

---

## How the Exploit Works

The exploit leverages **path traversal sequences (`..`)** in ADS paths within a RAR archive.  
This script creates a malicious RAR archive to demonstrate the CVE-2025-8088 vulnerability.  
It requires **Python** and access to `rar.exe` (WinRAR's command-line tool).

- Ensure `rar.exe` is in your system PATH or specify its path using the `--rar` argument.

## Requirements

- Python 3.6+
- WinRAR installed (for rar.exe)
- Windows NTFS filesystem (for ADS support)

---

### Command-Line Arguments

| Argument         | Description                                                                                   | Required? | Default                          |
|------------------|-----------------------------------------------------------------------------------------------|-----------|----------------------------------|
| `--decoy`        | Path to decoy file (existing or will be created)                                               | Yes       | -                                |
| `--payload`      | Path to harmless payload file (existing or will be created)                                    | Yes       | -                                |
| `--drop`         | Absolute path to benign folder (e.g., `C:\Users\you\Documents`)                             | Yes       | -                                |
| `--rar`          | Path to `rar.exe` (auto-discovered if omitted)                                                 | No        | Auto-discovered                  |
| `--out`          | Output RAR filename                                                                            | No        | `winrar_exploit.rar`      |
| `--workdir`      | Working directory                                                                              | No        | Current directory (`.`)          |
| `--placeholder_len` | Length of ADS placeholder (auto: ≥ max(len(injected), 128))                                 | No        | Auto-calculated                  |
| `--max_up`       | Number of `..` segments to prefix                                                              | No        | 16                               |
| `--keep_temp`     | Keep temporary base RAR file RAR                                                                 | No        | -                 |

---

## Example Usage

Create a malicious RAR archive with a decoy file, a payload, and a target drop folder, specifying the path to `rar.exe`:

```bash
python Exploit.py --decoy resume.txt --payload payload.bat --drop "C:\Users\you\Documents" --rar "C:\Program Files\WinRAR\rar.exe"
```

> **Disclaimer:** This tool is for educational and research purposes only. Do not use it to harm systems or networks. The author is not responsible for misuse or damage caused by this script.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →