EXPOSURES › CVE-2022-30333
CVE-2022-30333
CRITICAL ⌖ ON CISA KEV · EXPLOITEDRARLAB UnRAR on Linux/UNIX allows attackers to write arbitrary files during extraction due to a directory traversal vulnerability.
An attacker can exploit this flaw by crafting a malicious archive that, when extracted, overwrites system or application files. This is a critical, actively exploited vulnerability linked to ransomware campaigns, meaning DIB organizations must ensure UnRAR is patched or replaced to prevent supply-chain compromise and data integrity loss.
Shame score — A critical, actively exploited directory traversal flaw linked to ransomware that allowed arbitrary file writes, representing a severe, avoidable supply-chain risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.