A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.
| Vendor | Product | Versions |
|---|---|---|
| rarlab | winrar | 0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| dtsearch | dtsearch | cve_cpe | 95% |
| microsoft | windows | cve_cpe | 95% |
Updated description with new details on the exploitation method and added new IoCs and tags related to the ongoing attacks.
Updated description with details on two separate campaigns and added new CWE and MITRE ATT&CK technique.
Updated description with new attribution to Earth Dahu and SHADOW-EARTH-066 and added new tags related to cyber attacks in Ukraine.
Updated description with details on Gamaredon's exploitation of the vulnerability and added new CWE, IoCs, and tags.
Updated description with additional technical details and added CWE-22, while confirming the patch is version 7.13 or later.
Initial creation