Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-6218_WinRAR — Educational lab demonstrating CVE-2025-6218 path traversal in WinRAR. Includes a malicious RAR file and step-by-step guide to observe file overwrite outside extraction directory. | Kitploit
Tools/GitHubGitHub/speinador/cve-2025-6218_winrar
Vulnerability AnalysisExploitationWeb Application ExploitationLearning & EducationBinary ExploitationLabs & Practice
GitHubspeinador/cve-2025-6218_winrar

CVE-2025-6218_WinRAR

Educational lab demonstrating CVE-2025-6218 path traversal in WinRAR. Includes a malicious RAR file and step-by-step guide to observe file overwrite outside extraction directory.

View Repository
165501 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🧪 CVE-2025-6218: Path Traversal in WinRAR

📌 Description

This lab demonstrates how to exploit the CVE-2025-6218 vulnerability in vulnerable versions of WinRAR for Windows. This vulnerability allows a malicious .rar file to overwrite files outside the extraction directory using relative paths (..\..\), which can lead to code execution or manipulation of sensitive files.

⚠️ This lab is for educational purposes only. It must be run on an isolated virtual machine, disconnected from production networks.


🛡️ Vulnerable Versions

The vulnerability affects:

  • WinRAR 7.11 and earlier (including versions 6.x and some 5.x).
  • Vulnerable versions do not properly filter relative paths (..\..\) during extraction.
  • Does not affect WinRAR 7.12 and later.

It is strongly recommended to update to WinRAR 7.12 or later.


🎯 Lab Objective

  • Understand the concept of Path Traversal in compressed files.
  • Observe how a crafted .rar file can overwrite files outside the destination.
  • Highlight the importance of keeping software updated.

🧰 Requirements

  • Virtual machine with Windows 10 or 11.
  • WinRAR 7.11 or earlier.
  • Test file: C:\Users\victima\Desktop\importante.txt
  • WinRAR installed or executable (winrar.exe).
  • Malicious file archivo_exploit.rar (included in this ZIP).

🛠️ Environment Setup

  1. Install vulnerable WinRAR (e.g., 7.11).

  2. Create a legitimate file to overwrite:

    echo Archivo legítimo > "C:\Users\victima\Desktop\importante.txt"
    
  3. Extract archivo_exploit.rar from this lab into any folder (e.g., C:\temp).

  4. Open the .rar with WinRAR and extract it to any directory. The file will be extracted with a path like:

    ..\..\Users\victima\Desktop\importante.txt
    

    This will result in the original file being overwritten.


🔍 What should be observed?

  • Before extraction: importante.txt says “Legitimate file”.
  • After extracting the malicious .rar: it says “MALWARE INJECTED”.
  • The extraction did not occur on the desktop, but the file was overwritten due to the relative path.

✅ Solution

Update WinRAR to version 7.12 or later.


🧪 Repository Contents

FileDescription
archivo_exploit.rarCompressed file with escape path (..\..\)
importante.txtLegitimate file before the attack
crear_rar_malicioso.batDemo script to generate the .rar (if desired)
README.mdThis step-by-step guide

🧑‍🏫 Author

Explanation prepared by Sebastian Peinador for educational and research purposes in offensive cybersecurity.


📄 License

This material is distributed under the MIT license.


If you find it useful, don't forget to give ⭐ to the repo or share it!

Download Tool