KEVIntel
7.5
CVSS
High

CVE-2022-30333

PUBLISHED

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated...

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
RARLAB
Product
UnRAR
Published
May 09, 2022
EPSS

Description

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

windows linux android cisa malware metasploit

CVSS scores

CVSS v3.1 7.5 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVSS v2.0 5.0

AV:N/AC:L/Au:N/C:N/I:P/A:N

Exploitation status

Exploited in the wild

Recorded 2022-08-09 00:00:00 UTC · Source

Used in malware

Recorded 2026-06-02 14:08:25 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Aug 09, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

unrar_cve_2022_30333

metasploit · Created Unknown

Metasploit module for CVE-2022-30333

zimbra_unrar_cve_2022_30333

metasploit · Created Unknown

Metasploit module for CVE-2022-30333

aslitsecurity/Zimbra-CVE-2022-30333

github · Created 2022-07-26 13:28:12 UTC · 7 stars

Zimbra unrar vulnerability. Now there are already POC available, it is safe to release our POC.

J0hnbX/CVE-2022-30333

github · Created 2022-07-22 01:14:29 UTC · 2 stars

TheL1ghtVn/CVE-2022-30333-PoC

github · Created 2022-07-05 02:35:12 UTC · 13 stars

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Metasploit

  • Exploit Used in Malware