
Análise abrangente e prova de conceito para CVE-2025-6218 - vulnerabilidade de path traversal RCE no WinRAR afetando versões 7.11 e anteriores
⚠️ VULNERABILIDADE CRÍTICA - Exploração Ativa Confirmada
CVE-2025-6218 é uma vulnerabilidade crítica de path traversal no WinRAR que permite a execução de código arbitrário. Atualmente explorada por grupos APT como GOFFEE, Bitter (APT-C-08) e Gamaredon.
CVE-2025-6218 é uma vulnerabilidade CRÍTICA de path traversal no WinRAR para Windows que permite que atacantes executem código arbitrário.
| Aspecto | Detalhe |
|---|---|
| CVSS Score | 7.8 (High) |
| Versões Vulneráveis | WinRAR ≤ 7.11 (Windows only) |
| Plataformas | Windows 10, 11, Server |
| Usuários Afetados | ~500 milhões |
| Corrigido Em | WinRAR 7.12 (Junho 2025) |
| Status | 🔴 Exploração ATIVA |
| CISA KEV | Adicionado em 9 de Dezembro de 2025 |
Um atacante pode:
O WinRAR não valida corretamente os caminhos dos arquivos dentro de arquivos .rar especializados. Quando um usuário extrai um arquivo malformado, os arquivos podem ser escritos em caminhos arbitrários fora da pasta de extração pretendida usando sequências de path traversal (../ ou ..\\).
// Pseudocodice - WinRAR v7.11 (VULNERABILE) void extract_file(rar_entry *entry, char *dest_dir) { char final_path[MAX_PATH];
strcpy(final_path, dest_dir); // "C:\\Temp\\"
strcat(final_path, entry->filename); // + "..\\..\\..\\Windows\\System32\\malware.exe"
// ❌ ERRORE: Nessuna validazione del path traversal!
// final_path = "C:\\Temp\\..\\..\\..\\Windows\\System32\\malware.exe"
// Risolto come: "C:\\Windows\\System32\\malware.exe" ← EXPLOIT!
create_file(final_path); // File creato in directory non intesa
}
### Proteções Ausentes na v7.11
- ❌ Nenhum controle se o arquivo permanece dentro de `dest_dir`
- ❌ Nenhum filtro para sequências `..` ou `.`
- ❌ Nenhuma normalização de caminhos
- ❌ Nenhuma whitelist de diretórios permitidos
- ❌ Nenhuma validação de contenção
### A Correção na v7.12```c
// WinRAR v7.12 (PATCHED)
bool is_path_contained(char *path, char *base_dir) {
char canonical[MAX_PATH], canonical_base[MAX_PATH];
// Normalizza entrambi i percorsi
GetFullPathName(path, MAX_PATH, canonical, NULL);
GetFullPathName(base_dir, MAX_PATH, canonical_base, NULL);
// Verifica contenimento
if (strncmp(canonical, canonical_base, strlen(canonical_base)) != 0) {
return false; // Path esce dalla directory base
}
return true;
}
void extract_file_safe(rar_entry *entry, char *dest_dir) {
char final_path[MAX_PATH];
strcpy(final_path, dest_dir);
strcat(final_path, entry->filename);
// ✅ FIX: Verifica che il file rimane dentro dest_dir
if (!is_path_contained(final_path, dest_dir)) {
skip_extraction(); // Rifiuta estrazione
log_error("Path traversal detected!");
return;
}
create_file(final_path); // Adesso sicuro
}
Cartella di Estrazione: C:\Temp\Extract
Path nel RAR (craft): ..\..\..\..\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\payload.bat
Risoluzione Path: C:\Temp\Extract\.. = C:\Temp\ C:\Temp\.. = C:\ C:\.. = C:\ (non può andare oltre)
= C:\Users\\AppData\Roaming\...\Startup\payload.bat ✓
### Diagrama de Fluxo de Ataque```
┌─────────────────────────────────────────────┐
│ 1. Attaccante crea RAR con path craft │
│ es: ..\\..\\..\\Startup\\malware.bat │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 2. Distribuzione via spear-phishing │
│ Email mirata con allegato RAR │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 3. Vittima estrae archivio con WinRAR │
│ (versione ≤ 7.11) │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 4. WinRAR non valida path traversal │
│ File estratto in Startup folder │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 5. Al boot: payload eseguito │
│ RAT stabilisce C2 connection │
└─────────────────────────────────────────────┘
| Versão | Estado | Notas |
|---|---|---|
| ≤ 7.10 | 🔴 VULNERÁVEL | Todos os exploits funcionam |
| 7.11 | 🔴 VULNERÁVEL | Última versão vulnerável |
| 7.12 Beta 1+ | 🟢 CORRIGIDO | Correção de path traversal |
| 7.12+ | 🟢 CORRIGIDO | Versão estável com correção |
| UNIX / Android | ✅ NÃO AFETADO | Versões não-Windows não afetadas |
(Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion
wmic datafile where name="C:\\Program Files\\WinRAR\\WinRAR.exe" get Version
---
## 🌍 Cenários de Ataque
### Cenário 1: Bitter/APT-C-08 Spear-Phishing (CONFIRMADO ATIVO)
**Objetivo**: Governo, organizações militares, instituições estratégicas```
Email Phishing:
From: [email protected]
Subject: "Provision of Information for Sectoral for AJK.rar"
Attachment: Provision_of_Information.rar
Contenuto Archive:
├── Document.docx (esca legittima - report convincente)
└── ..\\..\\..\\..\\Users\\User\\AppData\\Roaming\\Microsoft\\Office\\STARTUP\\Template.dotm
(macro malato nascosto)
Esecuzione:
1. Vittima estrae RAR
2. WinRAR non valida path → Template.dotm finisce in Office STARTUP
3. Prossimo avvio Word → Macro eseguita automaticamente
4. PowerShell downloader attivato
5. C# Trojan scaricato: WmRAT, MiyaRAT, ZxxZ
6. C2 Server: johnfashionaccess.com
7. Capabilities:
- Keylogging
- Screenshot capture
- RDP credential stealing
- File exfiltration
- Lateral movement
Objetivo: Organizações governamentais russas``` RAR specializzato: ├── run.bat (path: ..\..\..\..\Windows\Startup\run.bat) └── legitimate_document.pdf (esca)