RARLAB WinRAR Code Execution Vulnerability
High CVSS 7.8 Listed in CISA KEV
Summary
RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- RARLAB:WinRAR
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2023-38831 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- http://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=232&cHash=c5bf79590657e32554c6683296a8e8aa; reference
- http://packetstormsecurity.com/files/174573/WinRAR-Remote-Code-Execution.html Exploit
- https://blog.google/threat-analysis-group/government-backed-actors-exploiting-winrar-vulnerability/ Exploit
- https://news.ycombinator.com/item?id=37236100 Issue Tracking
- https://www.bleepingcomputer.com/news/security/winrar-zero-day-exploited-since-april-to-hack-trading-accounts/ Exploit
- https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/ Exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-38831 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD