CVE-2023-38831
Summary
| CVE | CVE-2023-38831 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-23 17:15:43 UTC |
| Updated | 2026-08-05 05:16:38 UTC |
| Description | RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.978110000 probability, percentile 0.999000000 (date 2026-08-06)
CISA KEV: Listed on 2023-08-24; due 2023-09-14; ransomware use Known
Problem Types: CWE-345 | CWE-351 | n/a | CWE-351 CWE-351 Insufficient Type Distinction
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA Known Exploited Vulnerability
| Vendor | RARLAB |
|---|---|
| Product | WinRAR |
| Name | RARLAB WinRAR Code Execution Vulnerability |
| Required Action | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
| Notes | http://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=232&cHash=c5bf79590657e32554c6683296a8e8aa; https://nvd.nist.gov/vuln/detail/CVE-2023-38831 |
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WinRAR zero-day exploited since April to hack trading accounts | Hacker News | af854a3a-2127-422b-91ae-364da2661108 | news.ycombinator.com | Issue Tracking |
| WinRAR zero-day exploited since April to hack trading accounts | af854a3a-2127-422b-91ae-364da2661108 | www.bleepingcomputer.com | Exploit, Press/Media Coverage, Third Party Advisory |
| Government-backed actors exploiting WinRAR vulnerability | af854a3a-2127-422b-91ae-364da2661108 | blog.google | Exploit, Third Party Advisory |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| WinRAR Remote Code Execution ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| Cybersecurity Services, Solutions & Products. Global Provider | Group-IB | af854a3a-2127-422b-91ae-364da2661108 | www.group-ib.com | Exploit, Press/Media Coverage, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2023-08-24T00:00:00.000Z | CVE-2023-38831 added to CISA KEV |
There are currently no legacy QID mappings associated with this CVE.