Vulnerabilities
Vulnerable Software
Rarlab:  >> Winrar  >> 5.30  Security Vulnerabilities
In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNACEV2.dll) creates files and folders as written in the filename field even when WinRAR validator noticed the traversal attempt and requestd to abort the extraction process. the operation is cancelled only after the folders and files were created but prior to them being written, therefore allowing the attacker to create empty files and folders everywhere in the file system.
CVSS Score
5.5
EPSS Score
0.005
Published
2019-02-05
In WinRAR versions prior to and including 5.60, there is an out-of-bounds write vulnerability during parsing of crafted ACE and RAR archive formats. Successful exploitation could lead to arbitrary code execution in the context of the current user.
CVSS Score
7.8
EPSS Score
0.007
Published
2019-02-05
The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse file with a name similar to an extensionless filename that was selected by the user.
CVSS Score
7.4
EPSS Score
0.001
Published
2015-12-30


Contact Us

Shodan ® - All rights reserved