TechViral

Severe WinRAR Vulnerability Exposes Millions of Users: Patch Now Available

Share
Share

WinRAR, one of the most widely used compression tools on Windows systems, is facing a serious security threat. A recently discovered critical vulnerability in the popular software allows cybercriminals to execute malicious code on compromised machines. The flaw has been rated 7.8 out of 10 on the CVSS v3.1 severity scale, placing it in the high-risk category.

Although many similar applications exist, WinRAR has become an essential tool for millions of users worldwide. Its widespread use also makes it a frequent target for cyberattacks. As a result, its developers work diligently to release regular updates and security patches. This time, RARLAB has addressed one of the most severe flaws ever detected with the release of WinRAR 7.12, published on June 25, 2025.

The vulnerability, listed under the identifier CVE-2025-6218, was reported by Trend Micro’s Zero Day Initiative and discovered by researcher “whs3-detonator.” It allows attackers to manipulate file extraction paths, tricking the software into placing malicious files in different folders than intended. This technique increases the risk by concealing dangerous files within the system.

While exploiting this flaw requires some user interaction—such as opening a malicious file or visiting a compromised webpage—these scenarios are not uncommon. Downloading compressed content from unverified sources or being redirected through shady websites can easily lead to such exposures.

Unlike other, less critical issues such as high resource consumption, this vulnerability poses a direct threat to user safety by potentially enabling remote code execution without the user’s consent.

To check whether your version of WinRAR is vulnerable, open the program, go to the “Help” menu, and select “About WinRAR…”. If your version is older than 7.12, it is highly recommended that you update immediately to prevent attackers from exploiting this flaw—especially if you often decompress files from unknown sources.

RARLAB strongly urges all users to install the latest version as soon as possible to eliminate this dangerous security gap.

Share
Related Articles
Tech

Intel aims for redemption with its new core ultra 300 nova lake processors

After a rocky debut, Intel’s Core Ultra 200 series failed to meet...

TechViral

Meta strengthens safety measures to protect teens on Instagram

Meta, the parent company of Instagram, has announced new safety tools aimed...

ViralWar

Over 100 aid groups warn of widespread famine in Gaza

More than 100 international aid organizations warned on Wednesday of a rapidly...

PoliticsViral

United States withdraws from UNESCO again, citing “bias against Israel” and “divisive agendas”

The United States announced on Tuesday that it is once again withdrawing...

PoliticsViral

Report alleges “inhumane” conditions in South Florida immigration detention centers

Some immigrants held at the Federal Detention Center in Miami were allegedly...

Tech

LibreOffice accuses microsoft of using “unnecessarily complex” file formats to lock in users

The team behind LibreOffice has launched a scathing criticism of Microsoft, accusing...

ViralWar

Ukraine Faces Its Toughest Aerial Challenge Amid Massive Russian Drone Offensive

Ukraine’s air defenses are facing one of their most critical moments since...

Tech

Is Windows Defender Enough, or Do You Need an Additional Antivirus?

Most Windows users rely on a built-in security feature that comes preinstalled...