Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-8088 — Proof-of-concept demonstrating Alternate Data Stream (ADS) payload delivery via crafted WinRAR archives for educational research and controlled lab testing. | Kitploit
Tools/GitHubGitHub/walidpyh/cve-2025-8088
Payload GenerationExploitationLearning & EducationBinary ExploitationLabs & Practice
GitHubwalidpyh/cve-2025-8088

CVE-2025-8088

Proof-of-concept demonstrating Alternate Data Stream (ADS) payload delivery via crafted WinRAR archives for educational research and controlled lab testing.

View Repository
5221 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-8088 PoC (Educational Use Only)

Details about this CVE can be found at: https://nvd.nist.gov/vuln/detail/CVE-2025-8088

⚠️ Warning: This repository contains a proof-of-concept (PoC) for CVE-2025-8088.
It is intended for educational purposes, research, and lab environments only.
Do not use this code on systems you do not own or have explicit permission to test.


Overview

This project demonstrates how an Alternate Data Stream (ADS) payload can be embedded into a WinRAR archive.
It is designed to teach how certain Windows applications handle file streams and archive processing, specifically for research and lab testing.

Key Points:

  • Works with RAR5 format.
  • Supports multiple decoy files with one payload.
  • Recomputes all RAR header CRCs to ensure the archive is valid.
  • The payload is delivered via an ADS attached to the first decoy file.

Disclaimer

This PoC is not intended for malicious use. Misuse can be illegal and unethical.
Always run in a controlled lab environment or virtual machine.


Prerequisites

  • Windows Environment.
  • installed.
WinRAR
  • Python 3.10+

  • Installation

    Clone this repository:

    root@kitploit:~
    git clone https://github.com/walidpyh/CVE-2025-8088.git
    cd CVE-2025-8088
    

    Usage

    root@kitploit:~
    python main.py <payload_file> <output_rar> [--decoy <decoy_file1> <decoy_file2> ...]
    

    Examples:

    1. Using the default decoy:

    python main.py Updaters.exe Archive.rar

    1. Using custom decoy files:

    python main.py Updaters.exe Archive.rar --decoy README.md doc.txt

    Explanation:

    • <payload_file>: The file you want to deliver via ADS.
    • <output_rar>: The name of the generated RAR archive.
    • --decoy: Optional list of decoy files; only the first file carries the payload via ADS.

    How It Works

    1. Creates one or more decoy files.
    2. Attaches the payload to the first decoy using Alternate Data Streams (ADS).
    3. Builds a base RAR archive including all decoys.
    4. Patches the RAR headers to replace a placeholder with the target traversal path.
    5. Recomputes CRCs so the archive remains valid.
    Download Tool