CVE-2025-6218Active Exploitation(microsoft / windows)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch microsoft windows systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-12-30. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-22

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows
  • winrar

Threat summary

  • Active exploitation appears in 9 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 24 mentions across 21 observed days

What's happening

  • Active exploitation reported across 9 signals
  • Exploit tool or code specified in 7 signals
  • PoC mentioned or linked in 10 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • General: 8 classified signals
  • Peaked 19d ago at 3 mentions (2026-02-03); latest day: 1
  • 24 total mentions across 21 days

Affected systems

Products
windowswinrar

1 version affected across 2 products

Deep dive

Activity timeline24 mentions / 21d
01223Mentions · 2026-02-02: 1Mentions · 2026-02-03: 3Mentions · 2026-02-04: 1Mentions · 2026-02-06: 1Mentions · 2026-02-09: 1Mentions · 2026-02-16: 1Mentions · 2026-02-19: 2Mentions · 2026-02-20: 1Mentions · 2026-02-21: 1Mentions · 2026-03-05: 1Mentions · 2026-03-19: 1Mentions · 2026-04-10: 1Mentions · 2026-04-14: 1Mentions · 2026-05-07: 1Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Mentions · 2026-06-18: 1Mentions · 2026-06-23: 1Mentions · 2026-07-27: 1Mentions · 2026-08-08: 1Mentions · 2026-09-25: 1PoC Mentioned / Linked · 2026-02-02: 1PoC Mentioned / Linked · 2026-02-03: 2PoC Mentioned / Linked · 2026-02-04: 1PoC Mentioned / Linked · 2026-03-05: 1PoC Mentioned / Linked · 2026-03-19: 1PoC Mentioned / Linked · 2026-04-14: 1PoC Mentioned / Linked · 2026-05-07: 1PoC Mentioned / Linked · 2026-05-13: 1PoC Mentioned / Linked · 2026-09-25: 1Exploit Tool / Code · 2026-02-02: 1Exploit Tool / Code · 2026-03-05: 1Exploit Tool / Code · 2026-03-19: 1Exploit Tool / Code · 2026-04-14: 1Exploit Tool / Code · 2026-05-07: 1Exploit Tool / Code · 2026-05-13: 1Exploit Tool / Code · 2026-09-25: 1Active Exploitation · 2026-02-02: 1Active Exploitation · 2026-02-03: 1Active Exploitation · 2026-02-04: 1Active Exploitation · 2026-02-19: 1Active Exploitation · 2026-02-21: 1Active Exploitation · 2026-03-05: 1Active Exploitation · 2026-06-18: 1Active Exploitation · 2026-08-08: 1Active Exploitation · 2026-09-25: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-08-08: 1Technical Details · 2026-02-19: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-14: 1Technical Details · 2026-06-18: 1Technical Details · 2026-08-08: 102-0202-0402-0902-1902-2103-1904-1405-1306-1807-2709-25
Signal classification5 categories
Active Exploitation
833.3%
General
833.3%
Exploit
312.5%
PoC
312.5%
Disclosure
28.3%
Referenced assets18 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-021
Exploit1
2026-02-033
Active Exploitation1General1PoC1
2026-02-041
Active Exploitation1
2026-02-061
General1
2026-02-091
General1
2026-02-161
Disclosure1
2026-02-192
Active Exploitation1General1
2026-02-201
General1
2026-02-211
Active Exploitation1
2026-03-051
Active Exploitation1
2026-03-191
Exploit1
2026-04-101
General1
2026-04-141
Exploit1
2026-05-071
PoC1
2026-05-131
PoC1
2026-05-141
General1
2026-06-181
Active Exploitation1
2026-06-231
Disclosure1
2026-07-271
General1
2026-08-081
Active Exploitation1
2026-09-251
Active Exploitation1
Full discourse20 posts
  • Germán Fernández@1ZRR4H
    Exploit

    ♦️ Exposed #opendir on 187.77.173[.]118 port 8080 hosting AI-generated tools to analyze CVE-2025-6218 and test bypass variants against the official patch for WinRAR(?). The environment includes progress tracking and references to a business model aligned with 0-day development 👁️ On port 9999: multiple .bin files and "loaders" flagged as possible Meterpreter. [+] https://bazaar.abuse.ch/sample/3404b9e283fa22f8140855f5257853da1dc16380e8bb2f91409d3a71469784d9/ / @malwrhunterteam @HackingLZ @UK_Daniel_Card

    Post summary

    The post advertises an environment with AI-generated tools aimed at testing CVE‑2025‑6218 bypasses and includes links to potential exploit binaries, signalling possible exploitation activity without confirming real-world use.

    11811035415.5K
    37.3K followersView on X
  • Demon@volrant136
    General

    #APT #Sidewinder | #New #Variant | Targets #Pakistan Initial Dropper -> WinRAR ADS traversal vulnerabilities (CVE-2025-6218 & CVE-2025-8088) Decoy https://epms[.]ppra[.]gov[.]pk/public/tenders/invoice/TS0000000101E C2: docs.files-windows[.]top/j658K @500mk500 @MichalKoczwara

    Post summary

    The post announces a new Sidewinder APT variant that uses known WinRAR ADS traversal CVEs, but supplies no PoC, exploit code, or evidence of active exploitation, merely stating the vulnerability type.

    1611993.9K
    1.3K followersView on X
  • Askar Dyussekeyev@askardyuss
    Active Exploitation

    🚨 #ThreatIntel: New cyber espionage campaign targeting Pakistan's defense sector (Ministry of Defence / Air Force) 🇵🇰 An @anyrun_app sample reveals a malicious ZIP archive leveraging a WinRAR Path Traversal vulnerability (CVE-2025-6218) with NTFS Alternate Data Streams (ADS). 🛡️⚠️ 📦 Mechanics: 1. Victim opens a decoy invoice (Payment_Receipt.pdf). 2. Vulnerable extractor drops a hidden LNK via ADS traversal straight into the Startup folder. 3. The LNK executes obfuscated PowerShell to fetch a payload from docs[.]files-windows[.]top/j658K via Invoke-RestMethod. 🕸️ 4. It masks the attack by launching Chrome to a legitimate Pakistani gov URL. 🕵️‍♂️ 🔍 IoCs: ZIP MD5: 563442c7538069cc5630fed7a947d826 LNK MD5: 49069ca3d2bd90d40660ca3bdc517bff C2: docs.files-windows[.]top #CTI #MalwareAnalysis #CVE20256218 #Infosec

    Post summary

    The post reports an active cyber‑espionage campaign exploiting WinRAR’s CVE‑2025‑6218 via a malicious ZIP archive that uses NTFS ADS to drop an LNK to the Startup folder, delivering a payload and masking activity behind a legitimate URL.

    1301481.8K
    426 followersView on X
  • Szabolcs Schmidt@smica83
    Active Exploitation

    '5_18_9_1328_03.02.2026.rar' seen from Ukraine as a CVE-2025-6218 and 8088 @abuse_ch https://bazaar.abuse.ch/sample/c759e9d24a0ab4ddd73317ffa466d93ced1f6a8699e75dc1dd59f72c0a957aa2/ Domains: hxxps://be42.khlgj68234.workers(.)dev/ hxxps://awokent5.ease.workers(.)dev/ hxxps://mobx2i.inquiries.workers(.)dev/ @_CERT_UA https://t.co/UxaA0MsVl6

    Post summary

    Malware sample linked to CVE-2025-6218 and CVE-2025-8088 has been observed in Ukraine, indicating active exploitation.

    02082485
    3.1K followersView on X
  • Virus Bulletin@virusbtn
    General

    Robin Dost analyses a UAC-0226 sample, identifying it as a GIFTEDCROOK stealer variant. The chain starts with CVE-2025-6218 & CVE-2025-8088; a LNK launches a payload that decodes a binary, uses chunked data exfiltration & reconstructs its C2 at runtime. https://blog.synapticsystems.de/obfuscation-without-effort-breaking-a-uac-0226-giftedcrook-stealer/ https://t.co/8JaV1sDdie

    Post summary

    The tweet reports analysis of a UAC-0226 stealer sample involving CVE-2025‑6218 and CVE-2025‑8088, but provides none of the key evidence or details that would move it beyond a general mention.

    010731.3K
    61.3K followersView on X
  • Szabolcs Schmidt@smica83
    Disclosure

    'penis.11' is a ZIP, seen from Poland @abuse_ch CVE-2025-6218 and 8088 exploit. Some kind of Ransomware in it. 4472b8c557a3b5ad7b4a83034a4f7a40269074088bfde6902eda066c7dbfe77b https://bazaar.abuse.ch/sample/4472b8c557a3b5ad7b4a83034a4f7a40269074088bfde6902eda066c7dbfe77b https://t.co/9AKEoGWe6j

    Post summary

    A ransomware ZIP sample from Poland, containing CVE‑2025‑6218 and CVE‑8088, was posted on Abuse.ch; no PoC, exploit code, patch, or active‑exploitation details are provided.

    04051551
    3.8K followersView on X
  • Szabolcs Schmidt@smica83
    PoC

    '4_13_1_1389_28.04.2026.rar' @abuse_ch https://bazaar.abuse.ch/sample/97361a91ba80981ca549ed19b2e2b9250fed6231027cd15418578b3db76b02ab/ CVE-2025-6218, 8088 exploit. @500mk500 https://t.co/fYQDzyxioI

    Post summary

    The post shares a sample linked to CVE‑2025‑6218 and references an 8088 exploit, but provides no patch, active exploitation info, or detailed technical data.

    030611.6K
    3.8K followersView on X
  • Szabolcs Schmidt@smica83
    Active Exploitation

    'Soporte_Tecnico_Nahuel.rar' seen from Argentina @abuse_ch CVE-2025-6218 and 8088 exploit. https://bazaar.abuse.ch/sample/efcd02eb478c43356d3ad1860ece5c0dde126882eb892a96b7526a16ae77d212/ @1ZRR4H https://t.co/HlRFrehU4Y

    Post summary

    The tweet reports that CVE-2025-6218 and CVE-2025-8088 exploits were seen in use in Argentina, providing a sample link and indicating active exploitation in the wild.

    010631.5K
    3.2K followersView on X
  • Szabolcs Schmidt@smica83
    PoC

    '4_11_2_1537_03.02.2026.rar' seen from Ukraine as CVE-2025-6218 and 8088 @abuse_ch https://bazaar.abuse.ch/sample/30cabec3881131d8893b8c66d53ab133d73894509e05806e65b4cc8d8a1f7828/ @500mk500 https://t.co/pA2bcBhO3Z

    Post summary

    The tweet references a malware sample linked on Abuse.ch Bazaar associated with CVE-2025-6218 and CVE-2025-8088, indicating that a PoC exists.

    01071441
    3.1K followersView on X
  • Szabolcs Schmidt@smica83
    General

    'oxmaul.rar' seen from Latvia @abuse_ch ffa5c396a37ef0dbabf541cecc4e1bda84675eace39d2a8d2ccf355f08a9ca80 https://bazaar.abuse.ch/sample/ffa5c396a37ef0dbabf541cecc4e1bda84675eace39d2a8d2ccf355f08a9ca80/ CVE-2025-6218 and 8088 exploit. https://t.co/uKkZFwRcKW

    Post summary

    The tweet references a sample linked to CVE‑2025‑6218 and 8088 but provides no concrete PoC, exploit code, patches, or technical details.

    03041658
    3.8K followersView on X
  • t3ft3lb@t3ft3lb
    General

    #100DaysofYARA - Day 37 YARA rule to detect RAR samples exploiting CVE-2025-6218 👇 https://github.com/t3ft3lb/2026-100DaysofYARA/blob/main/day_37.yara https://t.co/djifDZgME5

    Post summary

    The tweet shares a YARA rule designed to detect RAR samples that exploit CVE‑2025‑6218, but it does not provide exploitation code, active attack evidence, or remediation guidance.

    01061441
    2.6K followersView on X
  • Szabolcs Schmidt@smica83
    Exploit

    '4_14_1_1762_02.02.2026.rar' seen from Ukraine as a CVE-2025-6218 and 8088 exploit @abuse_ch https://bazaar.abuse.ch/sample/5210e176a7a2b2d3e5d11a02a11f419a5d9ef96bfb3c518ca3f0e4fffe78f4a5/ @500mk500 https://t.co/2BlVipmdRa

    Post summary

    Sample of CVE-2025-6218 exploit observed in Ukraine, indicating the existence of functional exploit code and evidence of active use.

    01070629
    3.1K followersView on X
  • Szabolcs Schmidt@smica83
    General

    '1_12_8_1590_03.02.2026.rar' seen from Ukraine as a CVE-2025-6218 and 8088 @abuse_ch https://bazaar.abuse.ch/sample/9ee7695e040ef9f191f89548479e558c66004c6ecd5d2ae69d44d40e6a14a8c8/ @500mk500 https://t.co/8uEXo70Ivj

    Post summary

    The tweet reports a malware sample linked to CVE‑2025‑6218 and CVE‑2025‑8088 but offers no PoC, exploit code, patch information, or evidence of active exploitation.

    00070410
    3.1K followersView on X
  • Szabolcs Schmidt@smica83
    Active Exploitation

    '5_12_6_1292_02.02.2026.rar' seen from Ukraine as a CVE-2025-6218 and 8088 @abuse_ch https://bazaar.abuse.ch/sample/b6ef840b7161653d32f8f87b246209188c1aef5f074fe086c833d3e4d5a9a7a2/ @500mk500 https://t.co/mjKSWGoR0Y

    Post summary

    A malicious sample linked to CVE-2025-6218 and CVE-2025-8088 was observed in Ukraine, indicating active exploitation; no patch or detailed technical information is provided.

    00051427
    3.1K followersView on X
  • Szabolcs Schmidt@smica83
    Disclosure

    'Dogovor.rar' seen from Ukraine @abuse_ch https://bazaar.abuse.ch/sample/82e5a4dc50e843bf58e57c4e89f25123ef3a25f39e990a855fd5718e248b2d91/ CVE-2025-8088, CVE-2025-6218 @500mk500 https://t.co/lBnDjzViPj

    Post summary

    The tweet announces the presence of two new CVEs (CVE‑2025‑8088, CVE‑2025‑6218) linked to a malicious sample, but provides no exploitation code, patch details, or technical description.

    001401.1K
    3.1K followersView on X
  • Szabolcs Schmidt@smica83
    Active Exploitation

    '9190.rar' seen from Finland as a CVE-2025-6218, 8088 exploit @abuse_ch 10111b02ef35a94c8e8c1d42cf7870f20a59aeed1ddcc94eb592dd59c97bec5d https://bazaar.abuse.ch/sample/10111b02ef35a94c8e8c1d42cf7870f20a59aeed1ddcc94eb592dd59c97bec5d/

    Post summary

    The tweet reports a malware sample ('9190.rar') observed in Finland actively exploiting CVE-2025-6218, providing a sample hash and link to the Abuse.ch Bazaar repository for the exploit artifact.

    11011291
    3.9K followersView on X
  • ܛܔܔܔܛܔܛܔܛ@skocherhan
    General

    b4f2af6ed2916673bd17bac09f86ae5c CVE-2025-6218 CVE-2025-8088 https://t.co/bL4vwsH133

    Post summary

    The post merely lists two CVE identifiers and a link, without any further technical or operational information.

    00040281
    26.3K followersView on X
  • Szabolcs Schmidt@smica83
    Exploit

    'ideasserverRUST.rar' seen from Spain @abuse_ch CVE-2025-6218 and 8088 exploit https://bazaar.abuse.ch/sample/c7e557cc9feb2615b132aaa8a2a756cd5461c9975186a2e7b4a609fb63b84e09/ https://t.co/PCAuuNtBZS

    Post summary

    Abuse.ch reports a sample of an exploit for CVE‑2025‑6218 and CVE‑2025‑8088, linked via a .rar file observed in Spain.

    01010388
    3.5K followersView on X
  • 1024 Cyber Services@1024Cyber
    PoC

    CVE-2025-6218-POC - WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of WinRAR https://github.com/mulwareX/CVE-2025-6218-POC

    Post summary

    A proof‑of‑concept for a WinRAR directory traversal RCE is published on GitHub, but no active exploitation or patch information is reported.

    000011.1K
    40 followersView on X
  • ܛܔܔܔܛܔܛܔܛ@skocherhan
    Active Exploitation

    "A recent cyber campaign attributed to a Russian🇷🇺 threat actor has been harnessing a critical vulnerability in WinRAR, identified as CVE-2025-6218, to facilitate operations targeting Ukraine🇺🇦. This exploitation showcases a tactical approach through various file types and delivery mechanisms, indicative of the actor's intent to undermine Ukrainian systems. The threat actor deploys specially crafted PDF files that include HTA (HTML Application) scripts. These HTA files are executed upon opening the PDF, leading to payload execution and subsequent compromise of the victim's machine. The campaign employs a variety of documents, with filenames formatted to obscure their malicious intent. Several samples retrieved, such as "357-16230-25_24.10.2025.pdf" and "0135_11-967_11.11.2025.pdf," contain both ASCII text as well as HTML application components that automatically launch when the document is accessed." CVE-2025-8088 CVE-2025-6218 047cb26c6743c4a66f6e8a8d42bedc87 5d793beeffc5d60d4bdb7d0cd35c5094 d804b3f2e94afe10b3c6a3475f52e424 bd8bd746b35be94eb0223a24793c8b7b ca351801aaab5aa9cfea9ccfc918a4e3 0b1aff6971f999c1ffa3125608f093ab 9609197ae3c4e492e03850c8e11c3a99 dc658e6203add9352b8fb2f64334852e b9e2457d5d1def16a37958b29983d307 c659295754895056d29e89027a117f8d 2a0ae8e52f0a7157505f06af5b04323b f2195916410525d631a31447aa56c82f b57f15ed29beab97c623ec08aded6973 4e6f239440ee9f18b1361c6776966ec9 24784c11802ec72b4cdcf8f09f393072 13d38f8376d388140a98185e902144f4 02b1394a8ee31ed7770e275b060b0837 ae673f8e00fad94bf042d6432a7d1714 0752e1e4be66c0752c7b6ac01cdb8be3 58812a90572ebe34ab4df325270a6126 f4e3c1986e7f3f7d90c33fcfa887464c 0a4a5153eff06fe9cdd16a9ab621bea8 dd79f84a74f6858d11e0e614535b4c7a d6d1e1c0f3ef62ce0c01b2ff20ee1665 f40edd2236f3023272cf6c59864d71ed e63fa3dab3ecbe02742598cfd4bba46f 2a04a7584d90cff161be936b0b3f43c0 dd2214e2d3b6680ccc849f0b6ac75a03 b3ef7841d96e5643653707d3460dd924 04c44dc56980df576de4863458293b4c ba053b1357cb472539d6c9b9348f8e46 eaea21b33841a7b3e29657745d480886 40bbc60f6190efbf6cd5ce1624ff8992 52de7ee0117d8b3256d8a2193a1b493c c8abf5f03f8de16af910b64e949292de 0de31d625e0407acb3c3bc847a8d51ab d682e9d45132c9a92828d2fba59676f8 537dcb0f73ce1aebd7b5f07f4fcaff44 73990712c7ef207b30be96bb514aedd7 49236203088230724d731b5f80d0f16f 5bafb0ab8a6f408bba0684ac03dde813 3a35496cb89ebec78da91467e2bbf5a7 40ecef7276b5457f140f3805736aaeef 3dddaab21b3cbaa2ac3a50b394d4c36d 73211ebe0b8384bfa5e1adcb5ada21d3 0a0853f9bced51b0ae039df52b44e255 f2368a466c7a67ab3690736dd9d84f62 98f4d07fe705ddfb6fd348e4ca083fda c9e1087e29e4be493172205b95b310b5 7cd7847882bca995ee702f544035a715 f4756ac0ec170bf9650324fd3e3108c2 #Gamaredon

    Post summary

    A Russian‑affiliated campaign is actively exploiting CVE‑2025‑6218 via malicious PDFs containing HTA scripts to target Ukrainian systems; the post lacks mitigation details or PoC information.

    00010217
    26.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows---
Apprarlabwinrar---

Explore more