THREAT OPS › CVEs › CVE-2023-38831
CVE-2023-38831 — RARLAB WinRAR Code Execution Vulnerability
RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.
Vulnerability details
- Affected productsWinRAR
- KEV remediation due2023-09-14
Related reporting
- Exploits and vulnerabilities in Q2 2026securelist
- [NVD] CVE-2023-38831 (HIGH 7.8) — RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the bnvd