CVE-2023-38831 - RARLAB WinRAR
AI Vulnerability ContextRARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the beni...
Overview
A source-backed snapshot of this vulnerability.
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2023-38831
- Vendor/project
- RARLAB
- Product
- WinRAR
- Vulnerability name
- RARLAB WinRAR Code Execution Vulnerability
- Date added
- 2023-08-24
- Due date
- 2023-09-14
- Known ransomware campaign use
- Known
- CVSS v3
- 7.8
Exploit context
What the vulnerability is about.
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.
Source evidence
Original public records and references for this page.
Original source
Original source links
Open the public records and source datasets used for this page.
