EXPOSURES › CVE-2023-38831
CVE-2023-38831
CRITICAL ⌖ ON CISA KEV · EXPLOITEDRARLAB WinRAR contained an unpatched code execution vulnerability exploited in the wild by ransomware actors.
An unspecified vulnerability in WinRAR allowed attackers to execute code when users opened benign files within ZIP archives. This unpatched flaw was actively exploited in the wild and linked to ransomware campaigns, demonstrating the severe risk of relying on widely distributed software with known, unaddressed vulnerabilities. DIB organizations must rigorously patch all software, especially common utilities, and monitor for KEV-listed exploits to prevent similar compromises.
Shame score — RARLAB failed to patch a known, actively exploited vulnerability in a widely used product, directly enabling ransomware attacks and showing severe negligence in maintaining software security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.