PoC Archive PoC Archive

tag

WinRAR

  • CVE-2025-8088 misc HIGH 8.4 KEV Ransomware EPSS 95%

    WinRAR Windows Path Traversal via NTFS Alternate Data Streams (CVE-2025-8088)

    CVE-2025-8088 is a path traversal vulnerability in the Windows version of WinRAR. A specially crafted RAR archive abuses NTFS Alternate Data Streams (ADS) combined with ..\ traversal sequences so that, when opened or extracted by a vulnerable WinRAR build,…

    Patched 2026-07-01
  • CVE-2025-6218 misc HIGH KEV EPSS 89%

    WinRAR Archive Extraction Path Traversal (CVE-2025-6218)

    This PoC demonstrates CVE-2025-6218 in WinRAR, where a crafted archive extraction path can place files outside the intended destination directory. The provided batch script builds a ZIP archive that writes a .bat file into the current user's Startup folder.…

    Unverified 2026-05-15