CISA Warns of WinRAR 0-Day RCE Vulnerability Exploited in Attacks
A critical security vulnerability has been identified in WinRAR, a widely used file compression tool among Windows users. The vulnerability, designated as CVE-2025-6218 , is currently being exploited by attackers to compromise systems and execute…
A critical security vulnerability has been identified in WinRAR, a widely used file compression tool among Windows users. The vulnerability, designated as CVE-2025-6218 , is currently being exploited by attackers to compromise systems and execute unauthorized code.
The vulnerability is classified as a "path traversal" flaw, which involves WinRAR's failure to adequately verify filenames within compressed archives such as .zip or .rar files. This defect allows attackers to manipulate the extraction process, enabling files to be extracted outside the intended directory.
The exploitation of this vulnerability permits attackers to create files that circumvent the default safety of WinRAR's extraction procedures. Consequently, when a user opens a malicious file, the attacker can write files to unintended locations on the user's system, potentially allowing the execution of malicious code with the same privileges as the user.
Product: WinRAR (RARLAB) CVE ID: CVE-2025-6218 Vulnerability Type: Path Traversal (Remote Code Execution) CVSS v3.1 Score: 9.8 (Critical) CWE Classification: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory)
A critical security vulnerability has been identified in WinRAR, a widely used file compression tool among Windows users.
If exploited, this flaw permits attackers to execute code with the user's permission level. Users with administrative access may risk complete system control loss, data exfiltration, or ransomware installation.
The Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on December 9, 2025, indicating active exploitation in real-world scenarios. CISA mandates that federal agencies apply patches by December 30, 2025. Private organizations and individual users are strongly advised to update WinRAR immediately to mitigate the threat.
Users should download and install the latest version of WinRAR from the official RARLAB website. If updating is not feasible, discontinuation of the software's use is recommended until a fix is implemented.
Prompt action in updating the software will close the vulnerability, thereby preventing potential exploitation.
Based on reporting by Cyber Security News.
