KEVIntel
7.8
CVSS
High

CVE-2023-38831

PUBLISHED

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue...

Exploited in the wild Used in malware Low complexity
Vendor
RARLAB
Product
WinRAR
Published
Aug 23, 2023
EPSS

Description

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.

windows cisa malware ransomware metasploit

CVSS scores

CVSS v3.1 7.8 High

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2023-08-24 00:00:00 UTC · Source

Used in malware

Recorded 2023-08-24 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Aug 24, 2023

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

winrar_cve_2023_38831

metasploit · Created Unknown

Metasploit module for CVE-2023-38831

RomainBayle08/CVE-2023-38831

github · Created 2024-04-06 16:55:29 UTC · 0 stars

Nielk74/CVE-2023-38831

github · Created 2023-10-21 17:03:48 UTC · 0 stars

malvika-thakur/CVE-2023-38831

github · Created 2023-09-21 06:08:30 UTC · 3 stars

Proof-of-Concept (POC) of CVE-2023-38831 Zero-Day vulnerability in WinRAR

an040702/CVE-2023-38831

github · Created 2023-09-17 05:21:30 UTC · 0 stars

ameerpornillos/CVE-2023-38831-WinRAR-Exploit

github · Created 2023-09-12 16:01:17 UTC · 3 stars

Proof of concept (PoC) exploit for WinRAR vulnerability (CVE-2023-38831) vulnerability

Malwareman007/CVE-2023-38831

github · Created 2023-09-12 14:07:00 UTC · 9 stars

CVE-2023-38831 WinRaR Exploit Generator

xaitax/WinRAR-CVE-2023-38831

github · Created 2023-09-03 21:14:05 UTC · 12 stars

This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is executed, leading to code execution.

Mich-ele/CVE-2023-38831-winrar

github · Created 2023-09-01 16:45:42 UTC · 3 stars

CVE-2023-38831 winrar exploit builder

MorDavid/CVE-2023-38831-Winrar-Exploit-Generator-POC

github · Created 2023-08-30 19:55:11 UTC · 8 stars

This is a POC for the CVE-2023-3883 exploit targeting WinRAR up to 6.22. Modified some existing internet-sourced POCs by introducing greater dynamism and incorporated additional try-except blocks within the code.

z3r0sw0rd/CVE-2023-38831-PoC

github · Created 2023-08-30 11:52:23 UTC · 5 stars

Proof-of-Concept for CVE-2023-38831 Zero-Day vulnerability in WinRAR

ahmed-fa7im/CVE-2023-38831-winrar-expoit-simple-Poc

github · Created 2023-08-28 22:08:31 UTC · 11 stars

CVE-2023-38831 winrar exploit generator and get reverse shell

PascalAsch/CVE-2023-38831-KQL

github · Created 2023-08-28 15:26:14 UTC · 4 stars

KQL Hunting for WinRAR CVE-2023-38831

knight0x07/WinRAR-Code-Execution-Vulnerability-CVE-2023-38831

github · Created 2023-08-28 14:48:22 UTC · 41 stars

Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)

Maalfer/CVE-2023-38831_ReverseShell_Winrar-RCE

github · Created 2023-08-28 08:56:16 UTC · 22 stars

Pasos necesarios para obtener una reverse shell explotando la vulnerabilidad de winrar CVE-2023-38831 en versiones anteriores a 6.23.

HDCE-inc/CVE-2023-38831

github · Created 2023-08-28 04:56:10 UTC · 71 stars

CVE-2023-38831 PoC (Proof Of Concept)

ignis-sec/CVE-2023-38831-RaRCE

github · Created 2023-08-27 21:49:37 UTC · 115 stars

An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831, WinRAR RCE before versions 6.23

IR-HuntGuardians/CVE-2023-38831-HUNT

github · Created 2023-08-27 08:42:24 UTC · 2 stars

b1tg/CVE-2023-38831-winrar-exploit

github · Created 2023-08-25 09:44:08 UTC · 788 stars

CVE-2023-38831 winrar exploit generator

BoredHackerBlog/winrar_CVE-2023-38831_lazy_poc

github · Created 2023-08-24 16:03:07 UTC · 91 stars

lazy way to create CVE-2023-38831 winrar file for testing

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Metasploit