WinRAR patches bug letting malware launch from extracted archives

WinRAR patches bug letting malware launch from extracted archives

WinRAR has released a security update to fix a high-severity directory traversal vulnerability, CVE-2025-6218, that could allow malicious archives to execute code or steal data. Users are strongly advised to update to version 7.12 beta 1 to mitigate potential risks. #CVE-2025-6218 #WinRARUpdate

Keypoints

  • The vulnerability CVE-2025-6218 affects only Windows versions of WinRAR up to version 7.11.
  • A malicious archive could exploit the flaw to extract files into sensitive system locations.
  • Code execution or data theft could occur when malicious files are auto-run or launched at login.
  • The flaw was discovered by security researcher whs3-detonator and reported through Zero Day Initiative.
  • Users are recommended to upgrade to WinRAR 7.12 beta 1 immediately, regardless of platform.

Read More: https://www.bleepingcomputer.com/news/security/winrar-patches-bug-letting-malware-launch-from-extracted-archives/