
Analisi completa e proof-of-concept per CVE-2025-6218 - vulnerabilità di path traversal RCE in WinRAR che interessa le versioni 7.11 e precedenti
⚠️ CRITICAL VULNERABILITY - Active Exploitation Confirmed
CVE-2025-6218 è una vulnerabilità critica di path traversal in WinRAR che permette l'esecuzione di codice arbitrario. Attualmente sfruttata da APT groups come GOFFEE, Bitter (APT-C-08) e Gamaredon.
CVE-2025-6218 è una vulnerabilità CRITICA di path traversal in WinRAR per Windows che consente agli attaccanti di eseguire codice arbitrario.
| Aspetto | Dettaglio |
|---|---|
| CVSS Score | 7.8 (High) |
| Versioni Vulnerabili | WinRAR ≤ 7.11 (Windows only) |
| Piattaforme | Windows 10, 11, Server |
| Utenti Interessati | ~500 milioni |
| Patched In | WinRAR 7.12 (Giugno 2025) |
| Status | 🔴 Sfruttamento ATTIVO |
| CISA KEV | Aggiunto 9 Dicembre 2025 |
Un attaccante può:
WinRAR non valida correttamente i percorsi dei file all'interno di archivi .rar specializzati. Quando un utente estrae un archivio malformato, i file possono essere scritti in percorsi arbitrari al di fuori della cartella di estrazione prevista usando sequenze di path traversal (../ o ..\\).
// Pseudocodice - WinRAR v7.11 (VULNERABILE)
void extract_file(rar_entry *entry, char *dest_dir) {
char final_path[MAX_PATH];
strcpy(final_path, dest_dir); // "C:\\Temp\\"
strcat(final_path, entry->filename); // + "..\\..\\..\\Windows\\System32\\malware.exe"
// ❌ ERRORE: Nessuna validazione del path traversal!
// final_path = "C:\\Temp\\..\\..\\..\\Windows\\System32\\malware.exe"
// Risolto come: "C:\\Windows\\System32\\malware.exe" ← EXPLOIT!
create_file(final_path); // File creato in directory non intesa
}
dest_dir.. o .// WinRAR v7.12 (PATCHED)
bool is_path_contained(char *path, char *base_dir) {
char canonical[MAX_PATH], canonical_base[MAX_PATH];
// Normalizza entrambi i percorsi
GetFullPathName(path, MAX_PATH, canonical, NULL);
GetFullPathName(base_dir, MAX_PATH, canonical_base, NULL);
// Verifica contenimento
if (strncmp(canonical, canonical_base, strlen(canonical_base)) != 0) {
return false; // Path esce dalla directory base
}
return true;
}
void extract_file_safe(rar_entry *entry, char *dest_dir) {
char final_path[MAX_PATH];
strcpy(final_path, dest_dir);
strcat(final_path, entry->filename);
// ✅ FIX: Verifica che il file rimane dentro dest_dir
if (!is_path_contained(final_path, dest_dir)) {
skip_extraction(); // Rifiuta estrazione
log_error("Path traversal detected!");
return;
}
create_file(final_path); // Adesso sicuro
}
Cartella di Estrazione: C:\Temp\Extract
Path nel RAR (craft):
..\\..\\..\\..\\Users\\<user>\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\payload.bat
Risoluzione Path:
C:\\Temp\\Extract\\.. = C:\\Temp\\
C:\\Temp\\.. = C:\\
C:\\.. = C:\\ (non può andare oltre)
+ Users\\<user>\\...\\Startup\\payload.bat
= C:\\Users\\<user>\\AppData\\Roaming\\...\\Startup\\payload.bat ✓
┌─────────────────────────────────────────────┐
│ 1. Attaccante crea RAR con path craft │
│ es: ..\\..\\..\\Startup\\malware.bat │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 2. Distribuzione via spear-phishing │
│ Email mirata con allegato RAR │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 3. Vittima estrae archivio con WinRAR │
│ (versione ≤ 7.11) │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 4. WinRAR non valida path traversal │
│ File estratto in Startup folder │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 5. Al boot: payload eseguito │
│ RAT stabilisce C2 connection │
└─────────────────────────────────────────────┘
| Versione | Stato | Note |
|---|---|---|
| ≤ 7.10 | 🔴 VULNERABILE | Tutti gli exploit funzionano |
| 7.11 | 🔴 VULNERABILE | Ultima versione vulnerabile |
| 7.12 Beta 1+ | 🟢 PATCHED | Fix path traversal |
| 7.12+ | 🟢 PATCHED | Release stabile con fix |
| UNIX / Android | ✅ NOT AFFECTED | Versioni non-Windows non toccate |
# Metodo 1: PowerShell
(Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion
# Output:
# 7.11.0.0 → 🔴 VULNERABILE ⚠️
# 7.12.0.0 → 🟢 SAFE ✓
# Metodo 2: CMD
wmic datafile where name="C:\\\\Program Files\\\\WinRAR\\\\WinRAR.exe" get Version
# Metodo 3: GUI
# WinRAR → Help → About WinRAR → Verifica versione
Obiettivo: Governo, organizzazioni militari, istituzioni strategiche
Email Phishing:
From: [email protected]
Subject: "Provision of Information for Sectoral for AJK.rar"
Attachment: Provision_of_Information.rar
Contenuto Archive:
├── Document.docx (esca legittima - report convincente)
└── ..\\..\\..\\..\\Users\\User\\AppData\\Roaming\\Microsoft\\Office\\STARTUP\\Template.dotm
(macro malato nascosto)
Esecuzione:
1. Vittima estrae RAR
2. WinRAR non valida path → Template.dotm finisce in Office STARTUP
3. Prossimo avvio Word → Macro eseguita automaticamente
4. PowerShell downloader attivato
5. C# Trojan scaricato: WmRAT, MiyaRAT, ZxxZ
6. C2 Server: johnfashionaccess.com
7. Capabilities:
- Keylogging
- Screenshot capture
- RDP credential stealing
- File exfiltration
- Lateral movement
Obiettivo: Organizzazioni governative russe
RAR specializzato:
├── run.bat (path: ..\\..\\..\\..\\Windows\\Startup\\run.bat)
└── legitimate_document.pdf (esca)