tag
Alternate-Data-Streams
None assigned as of 2026-07-03
misc
HIGH
7-Zip RAR5 Mark-of-the-Web / ADS Full-Chain Bypass
7-Zip 26.01 on Windows mishandles RAR5 archives that contain crafted STM (stream) service records alongside a normal file entry. By naming one stream ::$DATA and another :Zone.Identifier:$DATA, an attacker can make the archive-provided data silently override…
Unverified
2026-07-03
CVE-2025-8088
misc
HIGH 8.4
KEV
Ransomware
EPSS 95%
WinRAR Windows Path Traversal via NTFS Alternate Data Streams (CVE-2025-8088)
CVE-2025-8088 is a path traversal vulnerability in the Windows version of WinRAR. A specially crafted RAR archive abuses NTFS Alternate Data Streams (ADS) combined with ..\ traversal sequences so that, when opened or extracted by a vulnerable WinRAR build,…
Patched
2026-07-01