CISA Known Exploited Vulnerability

CVE-2023-38831 Ransomware

RARLAB · WinRAR

RARLAB WinRAR Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-351
Ransomware Known

CISA description

RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.