Executive brief
RARLAB WinRAR versions prior to 6.23 contain a vulnerability where executable content within a folder can be processed when a user attempts to view a benign file of the same name within a ZIP archive. This flaw allows attackers to execute arbitrary code by spoofing file extensions in specially crafted archives.
Affected products
- RARLAB WinRAR before 6.23
Timeline
- 2023-04: exploited: Earliest reported exploitation in the wild.
- 2023-08-24: disclosed: Initial publication date and addition to CISA KEV catalog.
- 2023-08-24: kev added