Discover top-rated products handpicked just for you — at prices that make you smile

Time Yo Replace: WinRAR 7.13 Replace Fixes Important Home windows Safety Vulnerability

The extensively used file compression instrument for Home windows, WinRAR, has simply launched model 7.13 to handle a extreme safety vulnerability recognized as CVE-2025-8088. This flaw, discovered by ESET security researchers, particularly impacts the Home windows model of WinRAR, focusing on the UNRAR.dll library. The vulnerability permits attackers to craft malicious archive recordsdata that, when extracted by a consumer, trick WinRAR into writing recordsdata to a location of the attacker’s selecting as a substitute of the listing chosen by the consumer.

Exploitation of this vulnerability has been noticed within the wild, notably by way of phishing campaigns. Attackers have despatched emails containing specifically designed RAR archives that, when extracted, deposit executable recordsdata into delicate Home windows folders such because the Startup folder (%APPDATApercentMicrosoftWindowsStart MenuProgramsStartup). Any trojan horse positioned right here is routinely executed the subsequent time the system begins, leading to full compromise of the affected machine. This methodology allows attackers to achieve persistent entry and probably execute additional malicious actions, together with putting in distant entry trojans (RATs).

The first malware linked to exploitation of this flaw known as RomCom, a Distant Entry Trojan (RAT) related to cybercriminals recognized for social engineering assaults. These attackers disguise their malware as legit purposes, encouraging customers to obtain and set up compromised WinRAR variations. RomCom has been noticed focusing on organizations in numerous sectors, and there may be proof connecting its exploitation of CVE-2025-8088 to Russian-linked teams. Earlier assaults enabled distant code execution, knowledge exfiltration, and deployment of additional malware payloads.

You will need to observe that Unix variations of RAR and UnRAR, together with the variations for Android, are usually not affected by this vulnerability. The safety difficulty is confined to Home windows customers, and solely these with the affected variations (previous to 7.13) are in danger.

In contrast to some trendy software program, WinRAR doesn’t function computerized updates. Customers should go to the official WinRAR website and manually obtain and set up the most recent model to be protected. Failure to improve leaves programs uncovered to energetic threats.

Filed in Computers. Learn extra about , and .

Trending Merchandise

0
Add to compare
0
Add to compare
- 23% TP-Link AXE5400 Tri-Band WiFi 6E Ro...
Original price was: $199.99.Current price is: $154.99.

TP-Link AXE5400 Tri-Band WiFi 6E Ro...

0
Add to compare
- 23% ASUS 31.5” 4K HDR Eye Care Mon...
Original price was: $299.00.Current price is: $229.00.

ASUS 31.5” 4K HDR Eye Care Mon...

0
Add to compare
- 13% Wireless Keyboard and Mouse Combo, ...
Original price was: $39.99.Current price is: $34.99.

Wireless Keyboard and Mouse Combo, ...

0
Add to compare
- 15% Lenovo IdeaPad 1 Student Laptop, In...
Original price was: $349.00.Current price is: $296.65.

Lenovo IdeaPad 1 Student Laptop, In...

0
Add to compare
0
Add to compare
0
Add to compare
0
Add to compare
- 5% Logitech Media Combo MK200 Full-Siz...
Original price was: $19.99.Current price is: $18.99.

Logitech Media Combo MK200 Full-Siz...

0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

Hey Pick Pal
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart