VDB
BDU%3A2023-04958
BDU%3A2023-04958
PUBLISHED
CVSS 10 CRITICAL
Уязвимость файлового архиватора WinRAR, связанная с недостаточной проверкой входных данных, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| WinRAR GmbH | WinRAR | |
| rarlab | winrar | 0 |
| n/a | n/a | n/a |
Timeline
- Aug 24, 2023 PoC Published
- Aug 24, 2023 PoC Published
- Aug 29, 2023 CVE Published
- Aug 29, 2023 PoC Published
- Sep 7, 2023 PoC Published
- Sep 23, 2023 PoC Published
- Oct 20, 2023 CVE Updated
- Nov 10, 2023 PoC Published
- Nov 16, 2023 PoC Published
- Feb 2, 2024 PoC Published
- Feb 13, 2024 PoC Published
- Mar 1, 2024 PoC Published
References
- https://www.bleepingcomputer.com/news/security/winrar-zero-day-exploited-since-april-to-hack-trading-accounts/ url
- http://packetstormsecurity.com/files/174573/WinRAR-Remote-Code-Execution.html url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-38831 url
- https://news.ycombinator.com/item?id=37236100 url
- https://blog.google/threat-analysis-group/government-backed-actors-exploiting-winrar-vulnerability/ url
- https://3dnews.ru/1094712/google-obvinila-rossiyskih-i-kitayskih-hakerov-v-ekspluatirovanii-izvestnoy-uyazvimosti-winrar url
- https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/ url
- https://github.com/b1tg/CVE-2023-38831-winrar-exploit url
- https://vuldb.com/ru/?id.237878 url