Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit- — CVE-2025-8088 WinRAR Proof of Concept (PoC-Exploit) | Kitploit
Tools/GitHubGitHub/sxyrxyy/cve-2025-8088-winrar-proof-of-concept-poc-exploit-
Payload GenerationVulnerability AnalysisExploitationPenetration TestingLearning & EducationBinary Exploitation
GitHubsxyrxyy/cve-2025-8088-winrar-proof-of-concept-poc-exploit-

CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit-

CVE-2025-8088 WinRAR Proof of Concept (PoC-Exploit)

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
72311 year agoReviewed by Kitploit

CVE-2025-8088 WinRAR Proof of Concept (PoC-Exploit)

PoC

This repository contains a Proof of Concept (PoC) script for CVE-2025-8088, a path traversal vulnerability in WinRAR versions up to 7.12.
This PoC demonstrates how attackers could exploit the vulnerability to place malicious files outside the intended extraction directory using alternate data streams (ADSes) and crafted archive files.

Disclaimer: This tool is for educational and research purposes only. Do not use it to harm systems or networks. The author is not responsible for misuse or damage caused by this script.


Overview of CVE-2025-8088

CVE-2025-8088 (CVSS 8.4) is a path traversal vulnerability in WinRAR, affecting Windows versions up to 7.12, as well as related tools like UnRAR.dll and its portable source code.
The flaw allows attackers to embed malicious payloads in ADSes within specially crafted RAR files, enabling extraction to sensitive system locations (e.g., the Windows Startup folder).
This can lead to automatic execution of malicious files, such as DLLs or shortcut (.lnk) files, upon system reboot.

Key Details

  • Affected Versions: WinRAR ≤ 7.12
  • First Observed: Exploitation in the wild began on July 18, 2025 (per ESET)
  • Patch Availability: Fixed in WinRAR 7.13, released on July 30, 2025
  • Attackers: Linked to the Russia-aligned RomCom group (aka Storm-0978, Tropical Scorpius, UNC2596), known for cyberespionage and financially motivated attacks
  • Attack Method: Spearphishing emails with RAR files disguised as job applications, targeting finance, defense, manufacturing, and logistics sectors in Europe and Canada

How the Exploit Works

The exploit leverages path traversal sequences (..) in ADS paths within a RAR archive.
A seemingly harmless file (e.g., a resume) masks malicious ADS entries, which may include:


PoC Usage

This script creates a malicious RAR archive to demonstrate the CVE-2025-8088 vulnerability.
It requires Python and access to rar.exe (WinRAR's command-line tool).

Ensure rar.exe is in your system PATH or specify its path using the --rar argument.

Command-Line Arguments


Example Usage

Create a malicious RAR archive with a decoy file, a payload, and a target drop folder, specifying the path to rar.exe:

root@kitploit:~
python poc.py --decoy resume.txt --payload payload.bat --drop "C:\Users\you\Documents" --rar "C:\Program Files\WinRAR\rar.exe"

Attribution

This vulnerability was first observed in the wild by ESET on July 18, 2025, and is attributed to the RomCom hacking group.
For more on RomCom's tactics, see SOCRadar Threat Actor Intelligence.

Download Tool
ArgumentDescriptionRequired?Default
--decoyPath to decoy file (existing or will be created)Yes-
--payloadPath to harmless payload file (existing or will be created)Yes-
--dropAbsolute path to benign folder (e.g., C:\Users\you\Documents)Yes-
--rarPath to rar.exe (auto-discovered if omitted)NoAuto-discovered
--outOutput RAR filenameNocve-2025-8088-sxy-poc.rar
--workdirWorking directoryNoCurrent directory (.)
--placeholder_lenLength of ADS placeholder (auto: ≥ max(len(injected), 128))NoAuto-calculated
--max_upNumber of .. segments to prefixNo16
--base_outName for intermediate base RARNo<out>.base.rar