Junglewise Threat Intelligence

CVE-2023-38831: RARLAB WinRAR Code Execution Vulnerability

CVE-2023-38831 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-08-24

Technologies: RARLAB WinRAR. Vendors: RARLAB.

Executive brief

RARLAB WinRAR versions prior to 6.23 contain a vulnerability where executable content within a folder can be processed when a user attempts to view a benign file of the same name within a ZIP archive. This flaw allows attackers to execute arbitrary code by spoofing file extensions in specially crafted archives.

Affected products

  • RARLAB WinRAR before 6.23

Timeline

  • 2023-04: exploited: Earliest reported exploitation in the wild.
  • 2023-08-24: disclosed: Initial publication date and addition to CISA KEV catalog.
  • 2023-08-24: kev added

Related threats