VulnCity

WinRAR Path Traversal

  • شناسه CVE: CVE-2025-6218
  • شدت: بالا
  • امتیاز CVSS: 7.8
  • فروشنده/سازنده: RARLAB
Path TraversalWinRARArchiveMalicious File
A path traversal vulnerability in WinRAR allows attackers to write arbitrary files to any location on the filesystem when a victim extracts a maliciously crafted RAR archive.

## Vulnerability Overview
This vulnerability enables an attacker to create RAR archives that, when extracted by the victim, place files outside the intended extraction directory. This can be used to overwrite critical system files, drop malware in startup directories, or plant SSH keys for persistent access.

## Technical Details
- **Type:** Path Traversal / Directory Traversal (CWE-22)
- **Root Cause:** Improper sanitization of file paths within RAR archive entries. The vulnerability bypasses WinRAR's existing path traversal protections using Unicode normalization tricks and symbolic link chains.
- **Attack Vector:** Victim must open/extract the malicious archive (requires user interaction)
- **Payload Delivery:** Typically distributed via phishing emails with weaponized RAR attachments

## Real-World Exploitation
- Active exploitation observed in targeted phishing campaigns against government and defense organizations.
- APT groups using this vulnerability to drop RAT (Remote Access Trojan) payloads into Windows Startup folders.
- Over 500 million WinRAR users potentially affected.

## Exploitation Targets
- %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup (persistence)
- ~/.ssh/authorized_keys (Linux SSH access)
- Overwriting legitimate DLLs for DLL hijacking

نرم‌افزارهای تحت تأثیر

  • WinRAR < 7.10