
CVE-2025-8088 WinRAR Proof of Concept (PoC-Exploit)

This repository contains a Proof of Concept (PoC) script for CVE-2025-8088, a path traversal vulnerability in WinRAR versions up to 7.12.
This PoC demonstrates how attackers could exploit the vulnerability to place malicious files outside the intended extraction directory using alternate data streams (ADSes) and crafted archive files.
Disclaimer: This tool is for educational and research purposes only. Do not use it to harm systems or networks. The author is not responsible for misuse or damage caused by this script.
CVE-2025-8088 (CVSS 8.4) is a path traversal vulnerability in WinRAR, affecting Windows versions up to 7.12, as well as related tools like UnRAR.dll and its portable source code.
The flaw allows attackers to embed malicious payloads in ADSes within specially crafted RAR files, enabling extraction to sensitive system locations (e.g., the Windows Startup folder).
This can lead to automatic execution of malicious files, such as DLLs or shortcut (.lnk) files, upon system reboot.
The exploit leverages path traversal sequences (..) in ADS paths within a RAR archive.
A seemingly harmless file (e.g., a resume) masks malicious ADS entries, which may include:
This script creates a malicious RAR archive to demonstrate the CVE-2025-8088 vulnerability.
It requires Python and access to rar.exe (WinRAR's command-line tool).
Ensure rar.exe is in your system PATH or specify its path using the --rar argument.
Create a malicious RAR archive with a decoy file, a payload, and a target drop folder, specifying the path to rar.exe:
python poc.py --decoy resume.txt --payload payload.bat --drop "C:\Users\you\Documents" --rar "C:\Program Files\WinRAR\rar.exe"
This vulnerability was first observed in the wild by ESET on July 18, 2025, and is attributed to the RomCom hacking group.
For more on RomCom's tactics, see SOCRadar Threat Actor Intelligence.
| Argument | Description | Required? | Default |
|---|
--decoy | Path to decoy file (existing or will be created) | Yes | - |
--payload | Path to harmless payload file (existing or will be created) | Yes | - |
--drop | Absolute path to benign folder (e.g., C:\Users\you\Documents) | Yes | - |
--rar | Path to rar.exe (auto-discovered if omitted) | No | Auto-discovered |
--out | Output RAR filename | No | cve-2025-8088-sxy-poc.rar |
--workdir | Working directory | No | Current directory (.) |
--placeholder_len | Length of ADS placeholder (auto: ≥ max(len(injected), 128)) | No | Auto-calculated |
--max_up | Number of .. segments to prefix | No | 16 |
--base_out | Name for intermediate base RAR | No | <out>.base.rar |