CVE ID
CVE-2023-38831
Vulnerability Name
RARLAB WinRAR Code Execution Vulnerability
- Project: RARLAB
- Product: WinRAR
Date
- Date Added: 2023-08-24
- Due Date: 2023-09-14
Description
RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.
Known To Be Used in Ransomware Campaigns?
Known
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
http://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=232&cHash=c5bf79590657e32554c6683296a8e8aa; https://nvd.nist.gov/vuln/detail/CVE-2023-38831
Related Security News
- WinRAR Zero-Day Under Active Exploitation – Update to Latest Version Immediately
- CERT-UA Warns of HTA-Delivered C# Malware Attacks Using Court Summons Lures
- Russian hackers breach orgs to track aid routes to Ukraine
- Russian Hackers Exploit Email and VPN Vulnerabilities to Spy on Ukraine Aid Logistics
- Kaspersky Links Head Mare to Twelve, Targeting Russian Entities via Shared C2 Servers
- Russian cyber spies hide behind other hackers to target Ukraine
- Russian Turla hackers hit Starlink-connected devices in Ukraine
- APT-K-47 Uses Hajj-Themed Lures to Deliver Advanced Asyncshell Malware
- Cloudflare Warns of India-Linked Hackers Targeting South and East Asian Entities
- Hacktivists Exploits WinRAR Vulnerability in Attacks Against Russia and Belarus
Top comments (0)