Last week, WinRAR 7.13 dropped with a fix for a directory traversal vulnerability tracked as CVE 2025 8088. We now have more details on the exploit, thanks to work by researchers from ESET who discovered that attackers were actively abusing the flaw. The vulnerability exists within UNRAR.dll, a core library handling archive extraction. Attackers craft a malicious archive that can then trick the software into writing a file to a location they choose, instead of the directory a user...

Read the full article at Neowin