A new variant of the Zip Slip vulnerability has emerged, allowing malicious users to exploit path traversal flaws in widely used decompression. Attackers exploiting this vulnerability create malicious archives that contain specially crafted file names with relative paths. When an unsuspecting user or automated system extracts these archives, the files are written outside the intended extraction directory, potentially overwriting critical system or application binaries.

Initial reports indicate that attackers are using this technique to install backdoors and escalate privileges on Windows and Unix. Unlike traditional archives that restrict file locations to a subfolder, malicious ZIP files contain entries that, upon decompression, bypass inadequate path sanitization and drop payloads directly into system directories.
Zip Slip: Vulnerability Exploited for Attacks
Initially, the technique was used in internal penetration tests. However, campaigns attributed to the APT group RomCom and have shown exploitation in real-world, enterprise environments.
ASEC analysts discovered that the variant exploits the general purpose bit flag in the ZIP header to encode path separators that evade detection by signature-based scanners.
See also: Critical Chrome Vulnerability – Use After Free: Fix Immediately!
In one case, a contaminated email attachment delivered a ZIP archive that, when opened with an outdated decompression tool, silently replaced a legitimate startup script. Examination of the file structure revealed that the filename field, starting at offset 0x1E, contains path segments separated by percent-encoded slashes, which are only decoded during file creation.
Reverse engineering revealed that the malicious file exploited zipfile module to insert relative paths directly into the filename field.
The main vulnerabilities exploited by this technique are:
- CVE-2025-8088 – Affects WinRAR before version 7.13 and allows bypassing path validation via Alternate Data Stream traversal.
- CVE-2025-6218 – A remote code execution bug in WinRAR versions before 7.12 that bypasses relevant path filters when spaces are used.
- CVE-2022-30333 – Targets RARLAB Unrar before version 6.12 to replace SSH authorized_keys via paths “../../example”.
- CVE-2018-20250 – This abuses ACE format extraction in WinRAR before version 5.61 by bypassing the UNACEV2.dll filtering logic.
See also: Beware! New Sni5Gect attack targets 5G network

In addition to simple file replacement, this variant of the Zip Slip vulnerability supports the incorporation of executable scripts and DLLs designed to maintain a persistent presence on systems.
By writing payloads to startup folders or systemd service directories, attackers ensure execution on reboot. Detection is complicated, as many decompression tools do not canonicalize or validate canonical paths before writing.
Cybersecurity teams are urged to use decompression libraries with built-in path traversal checks, enforce extraction in sandbox environments, and update tools to versions released after August 2025.
The new Zip Slip variant highlights once again how vulnerable even the most basic software tools, such as decompression utilities, remain. The issue is not just limited to the spread of a technically sophisticated exploit, but also to the fact that thousands of users and businesses rely on software that is often not systematically updated. This inertia creates an ideal environment for exploiting old or neglected libraries.
See also: Cephalus Ransomware: Exploits RDP for Home Access
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The danger of the variant lies not only in the interception or corruption of data, but also in the ability of attackers to gain a permanent presence on critical systems. When a payload is placed in startup folders or service directories, it essentially becomes a “permanent resident” of the operating system, often escaping the attention of even well-configured antivirus solutions. This gives the perpetrators not only immediate control, but also long-term access, making recovery more difficult.
The emergence of this variant confirms that traditional exploitation techniques are not disappearing; they are simply evolving. The challenge for organizations and users is to adopt a more “zero trust” mindset towards every file and process, rather than relying on traditional, now-inadequate, defense models.
