Skip to main content

WinRAR vulnerabilities

3 published alerts for RARLAB WinRAR.

Actively exploited (KEV)Ransomware

CVE-2025-8088

RARLAB WinRAR Path Traversal Vulnerability

RARLAB WinRAR is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-8088). RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files. CISA remediation due date: 2025-09-02. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-38831

RARLAB WinRAR Code Execution Vulnerability

RARLAB WinRAR is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-38831). RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive. CISA remediation due date: 2023-09-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-20250

WinRAR Absolute Path Traversal Vulnerability

RARLAB WinRAR is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-20250). WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution CISA remediation due date: 2022-08-15. If you need help checking exposure, call (864) 335-9223.