{"id":9079,"date":"2025-12-10T10:03:40","date_gmt":"2025-12-10T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/10\/cisa-warns-of-winrar-0-day-rce-vulnerability-exploited-in-attacks\/"},"modified":"2025-12-10T10:03:40","modified_gmt":"2025-12-10T10:03:40","slug":"cisa-warns-of-winrar-0-day-rce-vulnerability-exploited-in-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/10\/cisa-warns-of-winrar-0-day-rce-vulnerability-exploited-in-attacks\/","title":{"rendered":"CISA Warns of WinRAR 0-Day RCE Vulnerability Exploited in Attacks"},"content":{"rendered":"<p>    CISA Warns of WinRAR 0-Day RCE Vulnerability Exploited in Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A high-priority warning regarding a critical security flaw in <a href=\"https:\/\/cybersecuritynews.com\/winrar-0-day-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">WinRAR<\/a>, the popular file compression tool used by millions of Windows users.<\/p>\n<p>The vulnerability, tracked as\u00a0<a href=\"https:\/\/cybersecuritynews.com\/winrar-0-day-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-6218<\/a>, is currently being exploited by attackers to compromise systems and execute malicious code.<\/p>\n<p>The specific flaw is known as a \u201cpath traversal\u201d vulnerability. In simple terms, WinRAR fails to properly check filenames in compressed archives (such as .zip or .rar files).<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-winrar-0-day-exploited\">\n<strong>WinRAR 0-Day<\/strong> <strong>Exploited<\/strong><br \/>\n<\/h2>\n<p>Allowing attackers to extract files outside the intended folder is a weakness also highlighted by CISA.<\/p>\n<p>By default, when you open a compressed file, its contents are stored in a specific folder. However, this bug allows a hacker to create a <a href=\"https:\/\/cybersecuritynews.com\/microsoft-defender-authentication-bypass\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious file<\/a> that tricks WinRAR.<\/p>\n<p>When a user opens this dangerous file, the attacker can \u201cescape\u201d the safe folder and write files to other sensitive areas of the computer.<\/p>\n<p>This allows the attacker to execute code with the same permission level as the user.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Feature<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Details<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Product<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">WinRAR (RARLAB)<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE ID<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><a href=\"https:\/\/cybersecuritynews.com\/apt-c-08-hackers-exploiting-winrar-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-6218<\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Vulnerability Type<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Path Traversal (Remote Code Execution)<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVSS v3.1 Score<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">9.8 (Critical)<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CWE Classification<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">CWE-22 (Improper Limitation of a Pathname to a Restricted Directory)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>If you are using an administrator account, the hacker could take complete control of your system, steal data, or install <a href=\"https:\/\/cybersecuritynews.com\/makop-ransomware-exploits-rdp-systems\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware<\/a>.<\/p>\n<p>CISA <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">added<\/a> this flaw to its\u00a0Known Exploited Vulnerabilities (KEV)catalog  on December 9, 2025. It is no longer a theoretical risk; it is a live threat.<\/p>\n<p>This is a significant move because CISA adds vulnerabilities to this list only when there is evidence that hackers are actively exploiting them in <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-leveraging-windows-and-linux-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">real-world attacks<\/a>.<\/p>\n<p>Due to the active threat, CISA has ordered federal agencies to <a href=\"https:\/\/cybersecuritynews.com\/ivanti-security-update-december\/\" target=\"_blank\" rel=\"noreferrer noopener\">patch<\/a> their systems by\u00a0December 30, 2025. However, private businesses and home users should not wait for that deadline. The solution is simple but urgent:\u00a0Update WinRAR immediately.<\/p>\n<p>Visit the official RARLAB website. Download and install the latest version of WinRAR. If you cannot update, CISA recommends discontinuing the use of the product until a fix is applied.<\/p>\n<p>By updating your software today, you close the door on attackers exploiting this <a href=\"https:\/\/cybersecuritynews.com\/samsung-zero-day-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero-day<\/a> flaw.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/winrar-0-day-rce-vulnerability-exploited\/\">CISA Warns of WinRAR 0-Day RCE Vulnerability Exploited in Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/winrar-0-day-rce-vulnerability-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA Warns of WinRAR 0-Day RCE Vulnerability Exploited in Attacks A high-priority warning regarding a critical security flaw in WinRAR, the popular file compression tool used by millions of Windows users. The vulnerability, tracked as\u00a0CVE-2025-6218, is currently being exploited by attackers to compromise systems and execute malicious code. The specific flaw is known as a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,2035,648,517],"tags":[130],"class_list":["post-9079","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-rce-vulnerability","category-vulnerability-news","category-zero-day","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9079"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9079"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9079\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9079"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9079"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9079"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}