Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-6218-WinRAR-RCE-POC — Comprehensive analysis and proof-of-concept for CVE-2025-6218 - WinRAR path traversal RCE vulnerability affecting versions 7.11 and earlier | Kitploit
Tools/GitHubGitHub/chrxstxqn/cve-2025-6218-winrar-rce-poc
Phishing ToolsPersistence MechanismsVulnerability AnalysisExploitationLateral MovementMalware AnalysisPenetration TestingLearning & EducationBinary Exploitation

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubchrxstxqn/cve-2025-6218-winrar-rce-poc

CVE-2025-6218-WinRAR-RCE-POC

Comprehensive analysis and proof-of-concept for CVE-2025-6218 - WinRAR path traversal RCE vulnerability affecting versions 7.11 and earlier

View Repository
21199 months agoNot yet reviewed

CVE-2025-6218: WinRAR Path Traversal RCE

CVE CVSS Score Platform License Status

⚠️ CRITICAL VULNERABILITY - Active Exploitation Confirmed

CVE-2025-6218 is a critical path traversal vulnerability in WinRAR that allows arbitrary code execution. Currently exploited by APT groups such as GOFFEE, Bitter (APT-C-08) and Gamaredon.


📋 Index

  • Overview
  • Technical Description
  • Exploit Mechanism
  • Vulnerable Versions
  • Attack Scenarios
  • Threat Actors
  • Proof of Concept
  • Detection & IOC
  • Mitigations
  • Timeline
  • Repository Structure
  • References

🎯 Overview

CVE-2025-6218 is a CRITICAL path traversal vulnerability in WinRAR for Windows that allows attackers to execute arbitrary code.

Main Impact

AspectDetail
CVSS Score7.8 (High)
Vulnerable VersionsWinRAR ≤ 7.11 (Windows only)
PlatformsWindows 10, 11, Server
Affected Users~500 million
Patched InWinRAR 7.12 (June 2025)
Status🔴 ACTIVE Exploitation
CISA KEVAdded December 9, 2025

Why is it Dangerous?

An attacker can:

  • ✅ Place files in sensitive folders (Startup, System32)
  • ✅ Execute code at system boot
  • ✅ Establish persistence without elevated privileges
  • ✅ Bypass antivirus (legitimate tool abuse)
  • ✅ Lateral movement in corporate networks

🔍 Technical Description

What is the Vulnerability?

WinRAR does not properly validate file paths inside specially crafted .rar archives. When a user extracts a malformed archive, files can be written to arbitrary paths outside the intended extraction folder using path traversal sequences (../ or ..\\).

Root Cause - The Bug```c

// Pseudocodice - WinRAR v7.11 (VULNERABILE) void extract_file(rar_entry *entry, char *dest_dir) { char final_path[MAX_PATH];

strcpy(final_path, dest_dir);         // "C:\\Temp\\"
strcat(final_path, entry->filename);  // + "..\\..\\..\\Windows\\System32\\malware.exe"

// ❌ ERRORE: Nessuna validazione del path traversal!
// final_path = "C:\\Temp\\..\\..\\..\\Windows\\System32\\malware.exe"
// Risolto come: "C:\\Windows\\System32\\malware.exe" ← EXPLOIT!

create_file(final_path);  // File creato in directory non intesa

}

### Missing Protections in v7.11

- ❌ No check if the file remains inside `dest_dir`
- ❌ No filter on `..` or `.` sequences
- ❌ No path normalization
- ❌ No whitelist of allowed directories
- ❌ No containment validation

### The Fix in v7.12```c
// WinRAR v7.12 (PATCHED)
bool is_path_contained(char *path, char *base_dir) {
    char canonical[MAX_PATH], canonical_base[MAX_PATH];
    
    // Normalizza entrambi i percorsi
    GetFullPathName(path, MAX_PATH, canonical, NULL);
    GetFullPathName(base_dir, MAX_PATH, canonical_base, NULL);
    
    // Verifica contenimento
    if (strncmp(canonical, canonical_base, strlen(canonical_base)) != 0) {
        return false;  // Path esce dalla directory base
    }
    return true;
}

void extract_file_safe(rar_entry *entry, char *dest_dir) {
    char final_path[MAX_PATH];
    strcpy(final_path, dest_dir);
    strcat(final_path, entry->filename);
    
    // ✅ FIX: Verifica che il file rimane dentro dest_dir
    if (!is_path_contained(final_path, dest_dir)) {
        skip_extraction();  // Rifiuta estrazione
        log_error("Path traversal detected!");
        return;
    }
    
    create_file(final_path);  // Adesso sicuro
}

💥 Exploit Mechanism

Path Traversal Explained```

Cartella di Estrazione: C:\Temp\Extract

Path nel RAR (craft): ..\..\..\..\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\payload.bat

Risoluzione Path: C:\Temp\Extract\.. = C:\Temp\ C:\Temp\.. = C:\ C:\.. = C:\ (non può andare oltre)

  • Users\\...\Startup\payload.bat

= C:\Users\\AppData\Roaming\...\Startup\payload.bat ✓

### Attack Flow Diagram```
┌─────────────────────────────────────────────┐
│  1. Attaccante crea RAR con path craft     │
│     es: ..\\..\\..\\Startup\\malware.bat   │
└─────────────────────────────────────────────┘
                    ↓
┌─────────────────────────────────────────────┐
│  2. Distribuzione via spear-phishing        │
│     Email mirata con allegato RAR          │
└─────────────────────────────────────────────┘
                    ↓
┌─────────────────────────────────────────────┐
│  3. Vittima estrae archivio con WinRAR     │
│     (versione ≤ 7.11)                       │
└─────────────────────────────────────────────┘
                    ↓
┌─────────────────────────────────────────────┐
│  4. WinRAR non valida path traversal       │
│     File estratto in Startup folder         │
└─────────────────────────────────────────────┘
                    ↓
┌─────────────────────────────────────────────┐
│  5. Al boot: payload eseguito              │
│     RAT stabilisce C2 connection            │
└─────────────────────────────────────────────┘

🔴 Vulnerable Versions

Compatibility Table

VersionStatusNotes
≤ 7.10🔴 VULNERABLEAll exploits work
7.11🔴 VULNERABLELast vulnerable version
7.12 Beta 1+🟢 PATCHEDPath traversal fix
7.12+🟢 PATCHEDStable release with fix
UNIX / Android✅ NOT AFFECTEDNon-Windows versions unaffected

How to Check Your Version```powershell

Metodo 1: PowerShell

(Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion

Output:

7.11.0.0 → 🔴 VULNERABILE ⚠️

7.12.0.0 → 🟢 SAFE ✓

Metodo 2: CMD

wmic datafile where name="C:\\Program Files\\WinRAR\\WinRAR.exe" get Version

Metodo 3: GUI

WinRAR → Help → About WinRAR → Verifica versione

## 🌍 Attack Scenarios

### Scenario 1: Bitter/APT-C-08 Spear-Phishing (CONFIRMED ACTIVE)

**Objective**: Government, military organizations, strategic institutions```
Email Phishing:
  From: [email protected]
  Subject: "Provision of Information for Sectoral for AJK.rar"
  Attachment: Provision_of_Information.rar

Contenuto Archive:
  ├── Document.docx (esca legittima - report convincente)
  └── ..\\..\\..\\..\\Users\\User\\AppData\\Roaming\\Microsoft\\Office\\STARTUP\\Template.dotm
      (macro malato nascosto)

Esecuzione:
  1. Vittima estrae RAR
  2. WinRAR non valida path → Template.dotm finisce in Office STARTUP
  3. Prossimo avvio Word → Macro eseguita automaticamente
  4. PowerShell downloader attivato
  5. C# Trojan scaricato: WmRAT, MiyaRAT, ZxxZ
  6. C2 Server: johnfashionaccess.com
  7. Capabilities:
     - Keylogging
     - Screenshot capture
     - RDP credential stealing
     - File exfiltration
     - Lateral movement

Scenario 2: GOFFEE Multi-Stage Payload

Objective: Russian government organizations``` RAR specializzato: ├── run.bat (path: ..\..\..\..\Windows\Startup\run.bat) └── legitimate_document.pdf (esca)

Download Tool