Skip to content
COOEY

FAIL › dossier

WinRAR

PRODUCT

· dossier confidence 20%

WinRAR, a widely used file archiver, has suffered from critical remote code execution vulnerabilities, highlighting the importance of timely patching and security awareness.

PROFILE
CategorysoftwareWhat they doWinRAR is a proprietary file archiver utility, known for its ability to create RAR archives, which are a Rosetta Stone format for various archive file formats. It is widely used for its ability to compress files and folders for efficient storage and distribution. Websitehttps://www.rarlab.com/ ↗
SECURITY POSTURE

WinRAR has faced multiple vulnerabilities, indicating a need for ongoing security monitoring and updates.

Notable failures
  • CVE-2018-20250: Path traversal vulnerability allowing remote code execution.
  • CVE-2023-38831: Unpatched code execution vulnerability exploited in the wild.
  • CVE-2025-8088: Path traversal vulnerability affecting Windows version of WinRAR.
  • CVE-2025-6218: Path traversal vulnerability allowing code execution in the context of the current user.
Patterns: Repeated unpatched edge-device RCEs.; Lack of automatic updates, leading to manual patching.
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2022-02-15 CVE-2018-20250 critical WinRAR's path traversal vulnerability allowed remote code execution and has been actively exploited in ransomware attacks, demonstrating a critical failure to control user input and validate file paths.
2023-08-24 CVE-2023-38831 critical RARLAB WinRAR contained an unpatched code execution vulnerability exploited in the wild by ransomware actors.
2025-12-09 CVE-2025-6218 high WinRAR RCE
2025-08-12 CVE-2025-8088 high WinRAR RCE due to path traversal
Open questions: How does WinRAR plan to address these recurring security issues? · What is the current security posture of WinRAR in light of these failures?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-23 03:43:51.139322+00:00