PT-2025-3122 · Unknown · Rar Extractor - Unarchiver
Zaid Hamad
·
Published
2025-01-21
·
Updated
2025-01-21
·
CVE-2024-55504
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
RAR Extractor - Unarchiver Free and Pro version 6.4.0
Description
The issue allows local attackers to inject arbitrary code, potentially leading to remote control and unauthorized access to sensitive user data via the
exploit combined.dylib component on MacOS.Recommendations
For RAR Extractor - Unarchiver Free and Pro version 6.4.0, consider disabling the
exploit combined.dylib component as a temporary workaround until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rar Extractor - Unarchiver