« Volver al listado

Rarlab

Rarlab Winrar: vulnerabilidades y CVE

Rarlab Winrar tiene 34 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 4 figuran en el catálogo de explotación activa de CISA.

CVE34
Últimos 12 meses3
Críticas0
Explotadas activamente4

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-6218Alta (7.8)90%⚠ Explotación activa21 jun 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to…
CVE-2025-8088Alta (8.4)94%⚠ Explotación activa8 ago 2025
—
CVE-2023-38831Alta (7.8)100%⚠ Explotación activa23 ago 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary…
CVE-2018-20250Alta (7.8)96%⚠ Explotación activa5 feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns,…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-14191Alta (7.8)0.44%—1 jul 2026
An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecItems vector is sized only when the first .rev file in a set is…
CVE-2019-25677Media (6.9)0.43%—5 abr 2026
WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng language file in the installation directory. Attackers can trigger the crash…
CVE-2025-52331Media (6.1)0.31%—12 nov 2025
Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to disclose user information such as the computer username, generated report directory, and IP…
CVE-2025-8088Alta (8.4)94%⚠ Explotación activa8 ago 2025
—
CVE-2014-125119Alta (8.4)1.7%—25 jul 2025
A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to inconsistencies between the Central Directory and Local File Header entries in ZIP files. When…
CVE-2025-6218Alta (7.8)90%⚠ Explotación activa21 jun 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to…
CVE-2025-31334Media (6.8)1.2%—3 abr 2025
Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted…
CVE-2024-36052Alta (7.5)0.75%—21 may 2024
RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899.
CVE-2023-40477Alta (7.8)11%—3 may 2024
RARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User…
CVE-2024-33899Alta (7.1)0.82%—29 abr 2024
RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via ANSI escape sequences.
CVE-2024-30370Media (4.3)1.2%—2 abr 2024
RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The-Web protection mechanism on affected installations of RARLAB WinRAR. User interaction is required…
CVE-2023-38831Alta (7.8)100%⚠ Explotación activa23 ago 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary…
CVE-2022-43650Alta (7.1)23%—29 mar 2023
This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR 6.11.0.0. User interaction is required to exploit this vulnerability in that the target must visit…
CVE-2018-20253Alta (7.8)4.0%—13 feb 2019
In WinRAR versions prior to and including 5.60, There is an out-of-bounds write vulnerability during parsing of a crafted LHA / LZH archive formats. Successful exploitation could lead to arbitrary code execution in the…
CVE-2018-20252Alta (7.8)3.6%—5 feb 2019
In WinRAR versions prior to and including 5.60, there is an out-of-bounds write vulnerability during parsing of crafted ACE and RAR archive formats. Successful exploitation could lead to arbitrary code execution in the…
CVE-2018-20251Media (5.5)32%—5 feb 2019
In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNACEV2.dll) creates files and folders as written in the…
CVE-2018-20250Alta (7.8)96%⚠ Explotación activa5 feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns,…
CVE-2015-5663Alta (7.4)0.91%—30 dic 2015
The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse file with a name similar to an extensionless filename that was selected by the user.
CVE-2008-7144Alta (10)2.3%—1 sept 2009
Multiple unspecified vulnerabilities in RARLAB WinRAR before 3.71 have unknown impact and attack vectors related to crafted (1) ACE, (2) ARJ, (3) BZ2, (4) CAB, (5) GZ, (6) LHA, (7) RAR, (8) TAR, or (9) ZIP files, as…
CVE-2006-3912Baja (2.1)5.7%—28 jul 2006
Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact.
CVE-2006-3845Alta (9.3)7.9%—25 jul 2006
Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive.
CVE-2005-4620Media (4.6)1.5%—31 dic 2005
Buffer overflow in WinRAR 3.50 and earlier allows local users to execute arbitrary code via a long command-line argument. NOTE: because this program executes with the privileges of the invoking user, and because remote…
CVE-2005-4474Media (5.1)2.0%—22 dic 2005
Buffer overflow in the "Add to archive" command in WinRAR 3.51 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by tricking the user into adding a file whose…
CVE-2005-3263Alta (7.5)3.7%—20 oct 2005
Stack-based buffer overflow in UNACEV2.DLL for RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via an ACE archive containing a file with a long name.
CVE-2005-3262Alta (7.5)8.8%—20 oct 2005
Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when WinRAR displays…
CVE-2005-3230Media (5.1)1.7%—14 oct 2005
Multiple interpretation error in unspecified versions of Panda Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local…
CVE-2005-3215Media (5.1)1.7%—14 oct 2005
Multiple interpretation error in unspecified versions of McAfee Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local…
CVE-2005-3227Media (5.1)1.7%—14 oct 2005
Multiple interpretation error in unspecified versions of UNA Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local…
CVE-2005-3229Media (5.1)1.7%—14 oct 2005
Multiple interpretation error in unspecified versions of ClamAV Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local…
CVE-2005-0331Baja (2.6)1.4%—2 may 2005
Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution6
  2. T1059 Command and Scripting Interpreter2
  3. T1005 Data from Local System1
  4. T1059.001 PowerShell1
  5. T1059.003 Windows Command Shell1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Rarlab