Netskope Threat Labs

FILE-OTHER RARLAB WinRAR directory traversal attempt

IPS-CFWIPS-SWG

2 SIDs: 65627, 65894

First seen
January 2026
Last seen
August 2026

Detects an archive exploiting CVE-2025-6218, a directory traversal in WinRAR that writes files outside the extraction directory. The crafted paths plant files into user or system locations during a normal extraction action.