
Educational lab demonstrating CVE-2025-6218 path traversal in WinRAR. Includes a malicious RAR file and step-by-step guide to observe file overwrite outside extraction directory.
This lab demonstrates how to exploit the CVE-2025-6218 vulnerability in vulnerable versions of WinRAR for Windows. This vulnerability allows a malicious .rar file to overwrite files outside the extraction directory using relative paths (..\..\), which can lead to code execution or manipulation of sensitive files.
⚠️ This lab is for educational purposes only. It must be run on an isolated virtual machine, disconnected from production networks.
The vulnerability affects:
..\..\) during extraction.It is strongly recommended to update to WinRAR 7.12 or later.
.rar file can overwrite files outside the destination.C:\Users\victima\Desktop\importante.txtwinrar.exe).archivo_exploit.rar (included in this ZIP).Install vulnerable WinRAR (e.g., 7.11).
Create a legitimate file to overwrite:
echo Archivo legítimo > "C:\Users\victima\Desktop\importante.txt"
Extract archivo_exploit.rar from this lab into any folder (e.g., C:\temp).
Open the .rar with WinRAR and extract it to any directory. The file will be extracted with a path like:
..\..\Users\victima\Desktop\importante.txt
This will result in the original file being overwritten.
importante.txt says “Legitimate file”..rar: it says “MALWARE INJECTED”.Update WinRAR to version 7.12 or later.
| File | Description |
|---|---|
archivo_exploit.rar | Compressed file with escape path (..\..\) |
importante.txt | Legitimate file before the attack |
crear_rar_malicioso.bat | Demo script to generate the .rar (if desired) |
README.md | This step-by-step guide |
Explanation prepared by Sebastian Peinador for educational and research purposes in offensive cybersecurity.
This material is distributed under the MIT license.
If you find it useful, don't forget to give ⭐ to the repo or share it!