PT-2023-4552 · Winrar · Winrar
Andrey Polovinkin
·
Published
2023-08-15
·
Updated
2025-10-08
·
CVE-2023-38831
CVSS v2.0
10
10
High
Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
WinRAR versions prior to 6.23
Description
WinRAR versions prior to 6.23 contain a vulnerability that allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. This occurs because a ZIP archive can include a benign file and a folder with the same name, and the contents of the folder, which may include executable content, are processed when attempting to access the benign file. This vulnerability has been actively exploited in the wild since April 2023 by multiple threat actors, including those linked to Russia and China, and has been used in attacks targeting various sectors, including cryptocurrency traders, government entities, and energy infrastructure. The vulnerability has been exploited by APT groups such as APT28, APT29, APT37, APT-K-47, UAC-0057, UAC-0099, and Head Mare. Attackers have used this vulnerability to deliver malware, including Remcos RAT, Agent Tesla, and PhantomRAT. The estimated number of affected devices is not specified.
Recommendations
Update WinRAR to version 6.23 or later.
Exploit
Fix
RCE
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Related Identifiers
BDU:2023-04958
CVE-2023-38831
Affected Products
Winrar
References · 465
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/winrar_cve_2023_38831.rb⭐ 35280 🔗 14253 · Exploit
- 🔥 https://github.com/b1tg/CVE-2023-38831-winrar-exploit⭐ 788 🔗 140 · Exploit
- 🔥 https://github.com/Garck3h/cve-2023-38831⭐ 129 🔗 22 · Exploit
- 🔥 https://github.com/ignis-sec/CVE-2023-38831-RaRCE⭐ 115 🔗 18 · Exploit
- 🔥 https://github.com/BoredHackerBlog/winrar_CVE-2023-38831_lazy_poc⭐ 92 🔗 17 · Exploit
- 🔥 https://github.com/HDCE-inc/CVE-2023-38831⭐ 70 🔗 13 · Exploit
- 🔥 https://github.com/knight0x07/WinRAR-Code-Execution-Vulnerability-CVE-2023-38831⭐ 41 🔗 12 · Exploit
- 🔥 https://github.com/Maalfer/CVE-2023-38831_ReverseShell_Winrar-RCE⭐ 22 🔗 7 · Exploit
- 🔥 https://github.com/xaitax/WinRAR-CVE-2023-38831⭐ 12 🔗 3 · Exploit
- 🔥 https://github.com/youmulijiang/evil-winrar⭐ 10 🔗 4 · Exploit
- 🔥 https://github.com/my-elliot/CVE-2023-38831-winrar-expoit-simple-Poc⭐ 11 🔗 1 · Exploit
- 🔥 https://github.com/Malwareman007/CVE-2023-38831⭐ 9 🔗 3 · Exploit
- 🔥 https://github.com/ahmed-fa7im/CVE-2023-38831-winrar-expoit-simple-Poc⭐ 11 🔗 1 · Exploit
- 🔥 https://github.com/MorDavid/CVE-2023-38831-Winrar-Exploit-Generator-POC⭐ 8 🔗 4 · Exploit
- 🔥 https://github.com/xk-mt/WinRAR-Vulnerability-recurrence-tutorial⭐ 4 🔗 1 · Exploit