RAR Anomaly Inspector 是一个只读的 PowerShell 工具,用于静态检查 RAR 存档,旨在检测与 CVE-2025-8088 (WinRAR RAR5 路径遍历) 相关的路径遍历异常。
该工具不会提取或执行存档内容。
..\)7z.exe(用于列出用户可见的文件).\anom-rar.ps1 .\suspicious.rar
RAR Anomaly Inspector
CVE : CVE-2025-8088 (WinRAR Path Traversal)
Author : Ilham
Source : https://github.com/ilhamrzr/RAR-Anomaly-Inspector
Mode : Static / Read-Only Inspection
Warning : Indicators only - NOT proof of exploitation
ScanTime : 2026-01-11 13:33:05
-------------------------------------------------------
=== Archive File Inventory (7-Zip read-only) ===
Files visible to the user:
- CVE-2025-8088.pdf
=== Suspicious Path Indicators Extraction ===
RAW suspicious path indicators (UNFILTERED):
- ..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\..\..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
- ..\..\..\..\..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
Total RAW indicators: 10
Sanitized logical paths (SAFE for copy-paste):
-> AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
=== Summary ===
Result: [!] ARCHIVE REQUIRES FURTHER INVESTIGATION
[!] High-risk archive structure detected (repeated deep traversal / ADS-style metadata)
Manual investigation hint:
- Review archive construction and intent.
- Do NOT execute extracted files directly.
- Treat repeated traversal as HIGH RISK.
Inspection completete.
低
无明显敏感目标的轻微异常
中
检测到遍历但无明确持久化路径
高
明确针对敏感目录的遍历
风险级别为启发式判断,并不表示利用成功。
不提取存档
不执行文件
不验证有效载荷
不保证利用性
适用于防御性分析和分类
适合蓝队、响应人员和研究人员
非利用框架
CVE-2025-8088
受影响:Windows 版 WinRAR ≤ 7.12
修复版本:WinRAR 7.13+
本工具仅供防御和教育目的使用。