Input validation error in WinRAR - CVE-2023-38831
Published: August 23, 2023 / Updated: October 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of file names inside .zip archives. A remote attacker can create a specially crafted archive that contains executable malicious files and spoof their file extension to look like .jpeg or .txt.
Note, the vulnerability is being actively exploited in the wild as of April 2023.
Affected software
How to mitigate CVE-2023-38831
Links to Public Exploits and PoC-codes
- Exploit #10646 - WinRAR version 6.22 - Remote Code Execution via ZIP archive (October 25, 2024)
- Exploit #10250 - Windows-X64-RAT (Remote Access Trojan (RAT) for Windows x64 using a combination of vulnerability CVE-2023-38831 (WinRAR < 6.23 vulnerability) and Shellcode exploitation technique.) (July 26, 2024)
- Exploit #9831 - evil-winrar (evil-winrar,CVE-2023-38831漏洞利用和社会工程学攻击框架 (evil-winrar, CVE-2023-38831 Vulnerability Exploitation and Social Engineering Attack Framework)) (May 23, 2024)
- Exploit #9779 - CVE-2023-38831_ReverseShell_Winrar-RCE (Pasos necesarios para obtener una reverse shell explotando la vulnerabilidad de winrar CVE-2023-38831 en versiones anteriores a 6.23.) (May 13, 2024)
- Exploit #9719 - CVE-2023-38831 (CVE-2023-38831 PoC (Proof Of Concept)) (April 19, 2024)
- Exploit #9718 - cve-2023-38831 (CVE-2023-38831 WinRAR) (April 19, 2024)
- Exploit #9673 - cve-2023-38831 (一款用于生成winrar程序RCE(即cve-2023-38831)的POC的工具。) (April 5, 2024)
- Exploit #9575 - CVE-2023-38831-winrar-expoit-simple-Poc (CVE-2023-38831 winrar exploit generator and get reverse shell) (February 27, 2024)
- Exploit #9459 - winDED (Exploit Development using python for CVE-2023-38831 (POC)) (December 26, 2023)
- Exploit #9321 - CVE-2023-38831-WinRAR-Exploit (Proof of concept (PoC) exploit for WinRAR vulnerability (CVE-2023-38831) vulnerability) (September 13, 2023)
- Exploit #9320 - CVE-Exploit (Find CVE and Exploit ) (September 13, 2023)
- Exploit #9319 - winrar-exploit-CVE-2023-38831-tool (CVE-2023-38831 zero-Day vulnerability in WinRAR exploited by cybercriminals to target traders) (September 13, 2023)
- Exploit #9318 - CVE-2023-38831 (CVE-2023-38831 WinRaR Exploit Generator) (September 13, 2023)
- Exploit #9298 - WinRAR CVE-2023-38831 Exploit (September 8, 2023)
- Exploit #9287 - CVE-2023-38831-winrar (CVE-2023-38831 winrar exploit builder) (September 4, 2023)
- Exploit #9282 - CVE-2023-38831-winrar-exploit () (September 4, 2023)
- Exploit #9281 - CVE-2023-38831_WinRAR (Steps needed to obtain a reverse shell exploiting the winrar vulnerability CVE-2023-38831 in versions prior to 6.23.) (September 4, 2023)
- Exploit #9280 - WinRAR-CVE-2023-38831 (This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is executed, leading to code execution.) (September 4, 2023)
- Exploit #9274 - WinrarExploit (CVE-2023-38831-WINRAR-EXPLOIT GENERATOR) (September 4, 2023)
- Exploit #9268 - CVE-2023-38831-PoC (Proof-of-Concept for CVE-2023-38831 Zero-Day vulnerability in WinRAR) (August 31, 2023)
- Exploit #9267 - CVE-2023-38831 (winrar exploit 6.22 <=) (August 31, 2023)
- Exploit #9264 - CVE-2023-38831-winrar-expoit-simple-Poc (CVE-2023-38831 winrar exploit generator and get reverse shell) (August 29, 2023)
- Exploit #9260 - CVE-2023-38831-winrar-exploit (CVE-2023-38831 winrar exploit generator) (August 28, 2023)
- Exploit #9259 - CVE-2023-38831-RaRCE (An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831, WinRAR RCE before versions 6.23) (August 28, 2023)