Junglewise Threat Intelligence

CVE-2022-30333: RARLAB UnRAR Directory Traversal Vulnerability

CVE-2022-30333 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-08-09

Vendors: RARLAB.

Executive brief

RARLAB UnRAR on Linux and UNIX systems contains a directory traversal vulnerability during the extraction (unpack) process. An attacker can exploit this to write arbitrary files to the filesystem, potentially leading to remote code execution as demonstrated by the creation of authorized_keys files.

Affected products

  • RARLAB UnRAR before 6.12

Timeline

  • 2022-08-09: disclosed
  • 2022-08-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-08-09: advisory: NVD publication date
  • 2022-08-09: exploited: Reported as exploited in the wild in CISA KEV catalog.

Related threats