A recent vulnerability in WinRAR allows remote code execution through specially crafted archive files, affecting all Windows versions of the software. Users are urged to update to version 7.12 Beta 1 or later to mitigate the risk of system compromise. #WinRAR #CVE2025-6218
Keypoints
- The vulnerability stems from insufficient validation of file paths within archive files.
- Attackers can embed directory traversal sequences to execute malicious code during extraction.
- Victims must open a malicious archive sent via phishing, malvertising, or compromised websites.
- All Windows versions of WinRAR are affected, while Unix and Android versions are not.
- Updating to WinRAR version 7.12 Beta 1 or later is strongly recommended to prevent exploitation.
Read More: https://gbhackers.com/winrar-vulnerability-exploited/