WinRAR flaw plants a hidden startup backdoor on Windows
A hidden flaw in WinRAR lets attackers secretly install a backdoor on your Windows PC. The backdoor, called STOCKSTAY, lets attackers spy on you and run commands without you noticing.
- Severity
- HighCVSS 3.1 · 8.8
- Fix
- Fixed in 7.13
- Affected versions
- through 7.12
- Weakness
- CWE-35
- Exploit likelihood
- 95% in 30 daysEPSS, higher than 100% of known flaws
- Affects
- WinRAR
- Exploited
- Yes, in the wildListed by CISA, used in ransomware
- Added to CISA list
- Aug 12, 2025
- Federal fix deadline
- Sep 2, 2025
How it works
Attackers send a fake RAR file that tricks WinRAR into writing a hidden backdoor file to your PC's startup folder, which runs every time you log in.
What to do
Check the installed WinRAR version. This advisory applies to versions older than 7.13 or versions older than 2023.01.
Update WinRAR to 7.13 or 2023.01 or newer. Then verify the installed version.
Technical details
CVE-2025-8088 is a CWE-35 path traversal flaw in the Windows build of WinRAR. The archive extraction routine does not sanitize relative path components that traverse upward out of the destination directory, allowing a crafted archive entry to write an arbitrary file to any path writable by the current user process. Discovered by ESET researchers Anton Cherepanov, Peter Kosinar, and Peter Strycek.
Fixed in WinRAR 7.13. EPSS exploitation probability is approximately 86 percent, reflecting confirmed in-the-wild use. The observed post-exploitation chain uses a Windows Startup folder shortcut for persistence and a reflectively loaded payload executed entirely in memory via PowerShell stages to avoid on-disk detection.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction Required Requires another user to take an action
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- win-rar.com · singlenewsview.html Release Notes VPNCentral
- vicarius.io · cve-2025-8088-mitigate-winrar-zero-day-using-srp-and-ifeo Mitigation Third Party Advisory
- arstechnica.com · high-severity-winrar-0-day-exploited-for-weeks-by-2-groups Press/Media Coverage
- support.dtsearch.com · dts0245.htm Third Party Advisory
- vicarius.io · cve-2025-8088-detect-winrar-zero-day Third Party Advisory
- cisa.gov · known-exploited-vulnerabilities-catalog US Government Resource
- welivesecurity.com · update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability Press/Media Coverage VPNCentral
- nvd.nist.gov · CVE-2025-8088 us government resource vdb entry
- cve.org · CVERecord vdb entry
- tenable.com · CVE-2025-8088 third party advisory vdb entry
- cvefeed.io · CVE-2025-8088 third party advisory vdb entry
- gbhackers.com · winrar-cve-2025-8088-exploited third party advisory
- thehackernews.com · gamaredon-exploits-winrar-to-deliver.html TheHackerNews
- thehackernews.com · winrar-flaw-exploited-by-russia-aligned.html TheHackerNews
- darkreading.com · russian-groups-winrar-flaw-ukrainian-orgs DarkReading
- securityaffairs.com · russian-apts-still-exploiting-patched-winrar-flaw-cve-2025-8088.html SecurityAffairs
- i0.wp.com · image-28.png SecurityAffairs
- trendmicro.com · old-winrar-flaw-fuels-attacks-on-ukraine.html SecurityAffairs VPNCentral
- i0.wp.com · image-29.png SecurityAffairs
- infosec.exchange · @securityaffairs SecurityAffairs
- securityaffairs.co · wordpress SecurityAffairs
- vpncentral.com · russian-linked-hackers-exploit-winrar-flaw-to-deploy-giftedcrook-stealer-against-ukraine VPNCentral
- cloud.google.com · exploiting-critical-winrar-vulnerability VPNCentral
- ppl-ai-file-upload.s3.amazonaws.com · STOCKSTAY-Backdoor-Uses-Malicious-RDP-Files-and-WinRAR-Exploit-to-Target-Ukraine.pdf Cyber Security News
- picussecurity.com · turla-secret-blizzard-apt-stockstay-and-kazuar-backdoors-explained Cyber Security News VPNCentral
- any.run · threat-intelligence-feeds Cyber Security News
- cloud.google.com · stockstay-turla-intelligence-gathering VPNCentral
- attack.mitre.org · G0010 VPNCentral