WinRAR Security Update – 11 August 2025

WinRAR has released a security update to fix a zero-day vulnerability affecting WinRAR 7.12 and prior.

The addressed vulnerability could allow the attacker to execute arbitrary code and gain access to the affected system.

WinRAR Remote Code Execution Vulnerability (CVE-2025-8088):

  • CVSS: 8.4
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Active
  • Consequences: Gain Access

It should be highlighted that security researchers have discovered that the zeroday vulnerability “CVE-2025-8088” is actively exploited in the wild.

Vulnerabilities

CVE-2025-8088

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

WinRAR Security Advisory

References