CVE Feed

    Dashboard / CVE / CVE-2023-38831

    CVE-2023-38831

    RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.

    Published:Aug 23, 2023
    Last Modified:Oct 31, 2025
    EPS:Aug 23, 2023
    EPSS Score:0.93814
    CVSS Score:7.8

    CISA Notification

    Description

    RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.

    Required Action:

    Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Notes:

    No extra notes provided.

    Due Date
    Sep 14, 2023
    1093 days ago
    Alert Date
    Aug 24, 2023
    1114 days ago

    Affected Products

    Vendor
    Rarlab
    Product
    Winrar

    Exploits

    http://packetstormsecurity.com/files/174573/WinRAR-Remote-Code-Execution.htmlhttps://blog.google/threat-analysis-group/government-backed-actors-exploiting-winrar-vulnerability/https://www.bleepingcomputer.com/news/security/winrar-zero-day-exploited-since-april-to-hack-trading-accounts/https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/http://packetstormsecurity.com/files/174573/WinRAR-Remote-Code-Execution.htmlhttps://blog.google/threat-analysis-group/government-backed-actors-exploiting-winrar-vulnerability/https://www.bleepingcomputer.com/news/security/winrar-zero-day-exploited-since-april-to-hack-trading-accounts/https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/https://github.com/ahmed-fa7im/CVE-2023-38831-winrar-expoit-simple-Pochttps://github.com/akhomlyuk/cve-2023-38831https://github.com/ameerpornillos/CVE-2023-38831-WinRAR-Exploithttps://github.com/an040702/CVE-2023-38831https://github.com/anelya0333/Exploiting-CVE-2023-38831https://github.com/asepsaepdin/CVE-2023-38831https://github.com/b1tg/CVE-2023-38831-winrar-exploithttps://github.com/Ben1B3astt/CVE-2023-38831_ReverseShell_Winrarhttps://github.com/BoredHackerBlog/winrar_CVE-2023-38831_lazy_pochttps://github.com/cristhiansm0/TXDXCristhian_2023-CVE-38831https://github.com/elefantesagradodeluzinfinita/cve-2023-38831https://github.com/Fa1c0n35/CVE-2023-38831-winrar-exploithttps://github.com/FirFirdaus/CVE-2023-38831https://github.com/Garck3h/cve-2023-38831https://github.com/GOTonyGO/CVE-2023-38831-winrarhttps://github.com/h3xecute/SideCopy-Exploits-CVE-2023-38831https://github.com/HDCE-inc/CVE-2023-38831https://github.com/Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784https://github.com/idkwastaken/CVE-2023-38831https://github.com/ignis-sec/CVE-2023-38831-RaRCEhttps://github.com/imbyter/imbyter-WinRAR_CVE-2023-38831https://github.com/IR-HuntGuardians/CVE-2023-38831-HUNThttps://github.com/kehrijksen/CVE-2023-38831https://github.com/khanhtranngoccva/cve-2023-38831-pochttps://github.com/knight0x07/WinRAR-Code-Execution-Vulnerability-CVE-2023-38831https://github.com/kuyrathdaro/cve-2023-38831https://github.com/kuyrathdaro/winrar-cve-2023-38831https://github.com/lightningspeed221/Winrar-Exploit-CVE-2023-38831https://github.com/Maalfer/CVE-2023-38831_ReverseShell_Winrar-RCEhttps://github.com/malvika-thakur/CVE-2023-38831https://github.com/Malwareman007/CVE-2023-38831https://github.com/MaorBuskila/Windows-X64-RAThttps://github.com/Mich-ele/CVE-2023-38831-winrarhttps://github.com/mishra0230/CVE-2023-38831https://github.com/ML-K-eng/CVE-2023-38831-Exploit-and-Detectionhttps://github.com/MorDavid/CVE-2023-38831-Winrar-Exploit-Generator-POChttps://github.com/MyStuffYT/CVE-2023-38831-POChttps://github.com/ngothienan/CVE-2023-38831https://github.com/Nielk74/CVE-2023-38831https://github.com/olowostandard1/CVE-2023-38831-WinRAR-Vulnerability-Analysishttps://github.com/ouoxii/Software-Testing-Final-Projecthttps://github.com/PascalAsch/CVE-2023-38831-KQLhttps://github.com/r1yaz/winDEDhttps://github.com/ra3edAJ/LAB-DFIR-cve-2023-38831https://github.com/RomainBayle08/CVE-2023-38831https://github.com/RonF98/CVE-2023-38831-POChttps://github.com/ruycr4ft/CVE-2023-38831https://github.com/s4m98/winrar-cve-2023-38831-poc-genhttps://github.com/sh770/CVE-2023-38831https://github.com/solomon12354/VolleyballSquid-----CVE-2023-38831-and-Bypass-UAChttps://github.com/SpamixOfficial/CVE-2023-38831https://github.com/sudo-py-dev/CVE-2023-38831https://github.com/technicalcorp0/CVE-2023-38831-Exploithttps://github.com/thegr1ffyn/CVE-2023-38831https://github.com/Tolu12wani/Demonstration-of-CVE-2023-38831-via-Reverse-Shell-Executionhttps://github.com/UnHackerEnCapital/PDFernetRemotelohttps://github.com/VictoriousKnight/CVE-2023-38831_Exploithttps://github.com/xaitax/WinRAR-CVE-2023-38831https://github.com/xk-mt/WinRAR-Vulnerability-recurrence-tutorialhttps://github.com/yangdayyy/cve-2023-38831https://github.com/yezzfusl/cve_2023_38831_scannerhttps://github.com/youmulijiang/evil-winrarhttps://github.com/z3r0sw0rd/CVE-2023-38831-PoC

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High