WinRAR Zero-Day Vulnerability (CVE-2025-8088) Exploited to Deploy RomCom Malware
HighWhat happened
A zero-day vulnerability in WinRAR, identified as CVE-2025-8088, was exploited by attackers to deploy the RomCom malware through specially crafted archive files.
Who is affected
Users of WinRAR versions prior to 7.13 who have extracted malicious archive files are at risk.
Why it matters
The exploitation of this vulnerability allows attackers to execute arbitrary code on affected systems, potentially leading to unauthorized access, data theft, and further malware deployment.
How it could have been prevented
Regularly updating software to the latest versions and exercising caution when extracting files from untrusted sources can mitigate such vulnerabilities.
Relevant professional terms
- Zero-Day Vulnerability
- A software flaw unknown to the vendor, exploited by attackers before a fix is available.
- Directory Traversal
- A security vulnerability that allows attackers to access restricted directories and execute commands outside of the intended directory structure.
Recommended reading: WinRAR Version 7.13 Release Notes
