PromptRiskDBThreat intelligence atlas

CVE-2023-38831 - RARLAB WinRAR

AI Vulnerability Context

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the beni...

Overview

A source-backed snapshot of this vulnerability.

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEVHIGH
CVE ID
CVE-2023-38831
Vendor/project
RARLAB
Product
WinRAR
Vulnerability name
RARLAB WinRAR Code Execution Vulnerability
Date added
2023-08-24
Due date
2023-09-14
Known ransomware campaign use
Known
CVSS v3
7.8
CWE-351

Exploit context

What the vulnerability is about.

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.

Source evidence

Original public records and references for this page.

Original source

Original source links

Open the public records and source datasets used for this page.