CVE-2014-125119
A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to inconsistencies between the Central Directory and Local File Header entries in ZIP files. When viewed in WinRAR, the file name from the Central Directory is displayed to the user, while the file from the Local File Header is extracted and executed. An attacker can leverage this flaw to spoof filenames and trick users into executing malicious payloads under the guise of harmless files, potentially leading to remote code execution.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.71%
- Percentil entre todas las CVEs puntuadas: 77
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution95 % - Impacto principal
T1059Command and Scripting Interpreterexecution90 % - Impacto secundario
T1036.005Match Legitimate Resource Name or Locationstealth85 %
Requiere interacción del usuario (UI:A) para abrir archivo ZIP preparado en WinRAR, ejecutando código mediante discrepancia entre encabezados. Suplantación de nombre (CWE-434) + ejecución.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-20, CWE-434
Referencias
- https://an7isec.blogspot.com/2014/03/winrar-file-extension-spoofing-0day.html
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/fileformat/winrar_name_spoofing.rb
- https://web.archive.org/web/20140625054244/http://intelcrawler.com/news-15
- https://web.archive.org/web/20141111142204/https://www.intelcrawler.com/report_2603.pdf
- https://www.rarlab.com/vuln_zip_spoofing_4.20.html
- https://www.vulncheck.com/advisories/winrar-filename-spoofing-rce
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-125119",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2014-125119",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-07-25T17:40:43.475752Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.4,
"Automatable": "NOT_DEFINED",
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "ACTIVE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "disclosure@vulncheck.com",
"affectedData": [
{
"vendor": "RARLab",
"modules": [
"Parsing Logic"
],
"product": "WinRAR",
"versions": [
{
"status": "affected",
"version": "3.80",
"lessThan": "3.91",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.11",
"lessThan": "5.00",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-07-25T16:15:26.507",
"references": [
{
"url": "https://an7isec.blogspot.com/2014/03/winrar-file-extension-spoofing-0day.html",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/fileformat/winrar_name_spoofing.rb",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://web.archive.org/web/20140625054244/http://intelcrawler.com/news-15",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://web.archive.org/web/20141111142204/https://www.intelcrawler.com/report_2603.pdf",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://www.rarlab.com/vuln_zip_spoofing_4.20.html",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://www.vulncheck.com/advisories/winrar-filename-spoofing-rce",
"source": "disclosure@vulncheck.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"description": [
{
"lang": "en",
"value": "CWE-20"
},
{
"lang": "en",
"value": "CWE-434"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to inconsistencies between the Central Directory and Local File Header entries in ZIP files. When viewed in WinRAR, the file name from the Central Directory is displayed to the user, while the file from the Local File Header is extracted and executed. An attacker can leverage this flaw to spoof filenames and trick users into executing malicious payloads under the guise of harmless files, potentially leading to remote code execution."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de suplantación de nombre de archivo en WinRAR al abrir archivos ZIP especialmente manipulados. El problema surge debido a inconsistencias entre las entradas del Directorio Central y la Encabezado de Archivo Local en los archivos ZIP. Al visualizarse en WinRAR, se muestra al usuario el nombre del archivo del Directorio Central, mientras que el archivo de la Encabezado de Archivo Local se extrae y se ejecuta. Un atacante puede aprovechar esta vulnerabilidad para suplantar nombres de archivo y engañar a los usuarios para que ejecuten payloads bajo la apariencia de archivos inofensivos, lo que podría provocar la ejecución remota de código."
}
],
"lastModified": "2026-06-17T00:04:30.057",
"sourceIdentifier": "disclosure@vulncheck.com"
}