HIGH🇵🇱 Wersja polska

CVE-2023-40477

CVSS 7.8v3.0pub. 2024-05-03upd. 2025-11-04

RARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of recovery volumes. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-21233.

CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Rarlab Winrar

    APP
    Rarlab
    < 6.23
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-8088HIGH8.4⚠ KEVsame product

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitra...

CVE-2025-6218HIGH7.8⚠ KEVsame product

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attack...

CVE-2023-38831HIGH7.8⚠ KEVsame product

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign fil...

CVE-2018-20250HIGH7.8⚠ KEVsame product

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filena...

CVE-2024-36052HIGH7.5same product

RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, ...