This popular Windows software used by millions has a serious security vulnerability – here’s what you need to know


- WinRAR flaw let crafted archives drop files outside target folder, including into Windows Startup
- New version 7.12 addresses critical path and HTML vulnerabilities
- Windows users urged to update WinRAR for improved file safety
Iconic file archiving tool WinRAR has received a security update addressing a serious flaw that could let attackers run arbitrary code on affected systems.
The vulnerability, tracked as CVE-2025-6218, was identified in the way WinRAR handles file paths within archives.
It was discovered by a researcher known as whs3-detonator, working with Trend Micro’s Zero Day Initiative.
Patch now
The issue exists in Windows versions of WinRAR, where a specially crafted archive can exploit path traversal during file extraction.
If a user opens such a file or visits a malicious site, the exploit can allow files to be placed in unintended directories, including sensitive ones like the Windows Startup folder.
This could cause malicious software to run automatically when the system boots.
RARLAB, the developer of WinRAR, has released version 7.12 to address this flaw.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The vulnerability does not affect versions of RAR or UnRAR for Unix or Android. Users are urged to update as soon as possible to reduce the risk of exploitation.
To stay protected from threats like this, it’s important to use the best antivirus software, reliable malware removal tools, and strong endpoint protection. Even well-known tools can have flaws, so running trusted security software and keeping all apps current helps reduce the risk of malware slipping through unnoticed.
The new WinRAR update also fixes an unrelated issue involving the “Generate Report” feature. In older versions, file names in generated HTML reports weren’t sanitized properly, which allowed basic HTML injection. That has now been corrected.
In addition to the security fixes, WinRAR 7.12 now tests recovery volumes during archive testing, giving users better confirmation that backup files are intact. It also preserves precise nanosecond timestamps when modifying Unix files on Windows.
You might also like
WinRAR flaw let crafted archives drop files outside target folder, including into Windows Startup New version 7.12 addresses critical path and HTML vulnerabilities Windows users urged to update WinRAR for improved file safety Iconic file archiving tool WinRAR has received a security update addressing a serious flaw that could let…
Recent Posts
- From centralized to distributed: why cloud architecture had to change
- Hydrow Discount Code: Save Up to $150 in July
- ChatGPT faceplants while translating Crunchyroll anime, and some viewers are demanding human localization
- Is the world’s largest CCTV surveillance camera vendor going to be the next Huawei? Canada bans Hikvision amidst security fears
- NYT Wordle today — answer and my hints for game #1475, Thursday, July 3
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021