login
quiescence.eu
Saltar al contenido

CVE-2023-38831

RARLAB WinRAR Code Execution Vulnerability

n/a
CVSS
97.8%
EPSS (exploit prob.)
99.9%
EPSS percentile
Yes
Actively exploited
Yes
Ransomware use
2023-08-24
Added

MITRE ATT&CK techniques

How this vulnerability maps to adversary behaviour, from the Center for Threat-Informed Defense's public CVE→ATT&CK mappings. Use it to check whether your detections already cover the technique.

TechniqueNameRelationship
T1204 User Execution exploitation technique
T1059.004 Unix Shell primary impact
T1005 Data from Local System secondary impact
T1041 Exfiltration Over C2 Channel secondary impact
T1053 Scheduled Task/Job secondary impact
T1105 Ingress Tool Transfer secondary impact
T1112 Modify Registry secondary impact
T1486 Data Encrypted for Impact secondary impact

Summary

RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.

Affected software

Vendor: RARLAB  ·  Product: WinRAR

Weakness types (CWE):

CWE-351

What to do

This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.

Related vulnerabilities in RARLAB

CVENameEPSSExploited
CVE-2022-30333 RARLAB UnRAR Directory Traversal Vulnerability 99.1% Yes
CVE-2018-20250 WinRAR Absolute Path Traversal Vulnerability 96.3% Yes
CVE-2025-8088 RARLAB WinRAR Path Traversal Vulnerability 94.6% Yes
CVE-2025-6218 RARLAB WinRAR Path Traversal Vulnerability 85.1% Yes

Is your domain exposed?

Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.

Get your free report

All information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.