CVE Explorer
CVE-2025-6218
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can lever
Known exploited
CISA KEV
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"WinRAR","vendor":"RARLAB","versions":[{"status":"affected","version":"7.11 (64-bit)"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:152670b5c258d7a6ef687fdf3ddb99b8284750d858fc6bf297c81b183f7bd633 · sha256:6e04d94280b5901f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.0"},"metric_type":"cvssV3_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:152670b5c258d7a6ef687fdf3ddb99b8284750d858fc6bf297c81b183f7bd633 · sha256:6e04d94280b5901f… · /containers/cna/metrics/0/cvssV3_0
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:152670b5c258d7a6ef687fdf3ddb99b8284750d858fc6bf297c81b183f7bd633 · sha256:6e04d94280b5901f… · /containers/cna/problemTypes/0/descriptions/0
Known exploitation assertions
2 source assertions{"cwes":["CWE-22"],"dateAdded":"2025-12-09","dueDate":"2025-12-30","knownRansomwareCampaignUse":"Unknown","notes":"https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=276&cHash=b5165454d983fc9717bc8748901a64f9 ; https://nvd.nist.gov/vuln/detail/CVE-2025-6218","product":"WinRAR","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in th…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:ed537de49b9986c0c1a52af8c45c907f85232bf2f6d0558f5524c8276686cb3f · sha256:16acee8334e59e44… · /vulnerabilities/185Open source location →
{"cwes":["CWE-22"],"dateAdded":"2025-12-09","dueDate":"2025-12-30","knownRansomwareCampaignUse":"Unknown","notes":"https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=276&cHash=b5165454d983fc9717bc8748901a64f9 ; https://nvd.nist.gov/vuln/detail/CVE-2025-6218","product":"WinRAR","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in th…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:215f3549a80bfdf83b7864db8afb93d22e4445b03fcf50c312365c4ff3ed6fc3 · sha256:635dff916c4092c0… · /vulnerabilities/188Open source location →
Source references
5 source assertions{"tags":["third-party-advisory"],"url":"https://foresiet.com/blog/apt-c-08-winrar-directory-traversal-exploit/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:152670b5c258d7a6ef687fdf3ddb99b8284750d858fc6bf297c81b183f7bd633 · sha256:6e04d94280b5901f… · /containers/adp/0/references/2
{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-6218"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:152670b5c258d7a6ef687fdf3ddb99b8284750d858fc6bf297c81b183f7bd633 · sha256:6e04d94280b5901f… · /containers/adp/0/references/1
{"tags":["third-party-advisory"],"url":"https://www.secpod.com/blog/archive-terror-dissecting-the-winrar-cve-2025-6218-exploit-apt-c-08s-stealth-move/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:152670b5c258d7a6ef687fdf3ddb99b8284750d858fc6bf297c81b183f7bd633 · sha256:6e04d94280b5901f… · /containers/adp/0/references/0
{"name":"vendor-provided URL","tags":["vendor-advisory"],"url":"https://www.win-rar.com/singlenewsview.html?&tx_ttnews%5Btt_news%5D=276&cHash=388885bd3908a40726f535c026f94eb6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:152670b5c258d7a6ef687fdf3ddb99b8284750d858fc6bf297c81b183f7bd633 · sha256:6e04d94280b5901f… · /containers/cna/references/1
{"name":"ZDI-25-409","tags":["x_research-advisory"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-25-409/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:152670b5c258d7a6ef687fdf3ddb99b8284750d858fc6bf297c81b183f7bd633 · sha256:6e04d94280b5901f… · /containers/cna/references/0
Attribution and limitations
- CISA Known Exploited Vulnerabilities JSON: CISA named for provenance; do not use CISA/DHS marks or imply endorsement Source →
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.