Vulnerability detail
Enriched intelligence for a single CVE
High
CVE-2023-38831
PUBLISHEDRARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue...
- Vendor
- RARLAB
- Product
- WinRAR
- Published
- Aug 23, 2023
- EPSS
- —
Description
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.
CVSS scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
SSVC decision points
- Exploitation
- active
- Automatable
- No
- Technical impact
- total
References
- https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/
- https://www.bleepingcomputer.com/news/security/winrar-zero-day-exploited-since-april-to-hack-trading-accounts/
- https://news.ycombinator.com/item?id=37236100
- http://packetstormsecurity.com/files/174573/WinRAR-Remote-Code-Execution.html
- https://blog.google/threat-analysis-group/government-backed-actors-exploiting-winrar-vulnerability/
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CISA | Aug 24, 2023 |
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/winrar_cve_2023_38831.rb | Apr 28, 2025 |
Potential proof of concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2024-04-06 16:55:29 UTC · 0 stars
github · Created 2023-10-21 17:03:48 UTC · 0 stars
github · Created 2023-09-21 06:08:30 UTC · 3 stars
Proof-of-Concept (POC) of CVE-2023-38831 Zero-Day vulnerability in WinRAR
github · Created 2023-09-17 05:21:30 UTC · 0 stars
github · Created 2023-09-12 16:01:17 UTC · 3 stars
Proof of concept (PoC) exploit for WinRAR vulnerability (CVE-2023-38831) vulnerability
github · Created 2023-09-12 14:07:00 UTC · 9 stars
CVE-2023-38831 WinRaR Exploit Generator
github · Created 2023-09-03 21:14:05 UTC · 12 stars
This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is executed, leading to code execution.
github · Created 2023-09-01 16:45:42 UTC · 3 stars
CVE-2023-38831 winrar exploit builder
github · Created 2023-08-30 19:55:11 UTC · 8 stars
This is a POC for the CVE-2023-3883 exploit targeting WinRAR up to 6.22. Modified some existing internet-sourced POCs by introducing greater dynamism and incorporated additional try-except blocks within the code.
github · Created 2023-08-30 11:52:23 UTC · 5 stars
Proof-of-Concept for CVE-2023-38831 Zero-Day vulnerability in WinRAR
github · Created 2023-08-28 22:08:31 UTC · 11 stars
CVE-2023-38831 winrar exploit generator and get reverse shell
github · Created 2023-08-28 15:26:14 UTC · 4 stars
KQL Hunting for WinRAR CVE-2023-38831
github · Created 2023-08-28 14:48:22 UTC · 41 stars
Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)
github · Created 2023-08-28 08:56:16 UTC · 22 stars
Pasos necesarios para obtener una reverse shell explotando la vulnerabilidad de winrar CVE-2023-38831 en versiones anteriores a 6.23.
github · Created 2023-08-28 04:56:10 UTC · 71 stars
CVE-2023-38831 PoC (Proof Of Concept)
github · Created 2023-08-27 21:49:37 UTC · 115 stars
An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831, WinRAR RCE before versions 6.23
github · Created 2023-08-27 08:42:24 UTC · 2 stars
github · Created 2023-08-25 09:44:08 UTC · 788 stars
CVE-2023-38831 winrar exploit generator
github · Created 2023-08-24 16:03:07 UTC · 91 stars
lazy way to create CVE-2023-38831 winrar file for testing
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Exploit Used in Malware
-
Added to KEVIntel
-
Detected by Metasploit