LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-38831: RARLAB WinRAR Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 24, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Sep 14, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-38831 to its Known Exploited Vulnerabilities catalog on Aug 24, 2023, with a federal patch deadline of Sep 14, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.

CVE-2023-38831 is a code execution vulnerability in RARLAB WinRAR. It allows an attacker to execute code when a user attempts to view a benign file inside a specially crafted ZIP archive. This matters because WinRAR is commonly installed on Windows endpoints for handling compressed files, and successful exploitation can give an attacker a foothold for further activity, including ransomware operations that have already leveraged this issue.

Defenders should treat it as a high-priority client-side risk: users routinely open archives from email or downloads, and the vulnerability turns an ordinary viewing action into potential code execution. Confirm all version and patch details against the vendor advisory.

How it works

The weakness is classified as CWE-351. In broad terms for this class of archive-handling flaws, the software fails to properly distinguish between file types or contents inside a ZIP container. An attacker prepares a malicious ZIP archive that appears to contain ordinary, benign files. When a user opens or previews one of those files with the vulnerable WinRAR version, the application processes the archive in a way that allows attacker-controlled code to run on the system.

No further exploit mechanics are specified in the available public summary; the core abuse path is simply that viewing a file the user believes is harmless triggers code execution. Specifics of how the archive is structured must be confirmed against the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

WinRAR is typically installed on Windows workstations and servers used by individuals or teams that regularly extract or inspect compressed archives. It is often present on developer, finance, legal, and general office endpoints.

How to remediate

Patch first. Apply the vendor-supplied update for WinRAR exactly as described in the RARLAB advisory. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

This vulnerability has been used in ransomware campaigns. If exploitation is suspected or confirmed, treat the incident as a potential breach: isolate affected hosts, preserve forensic evidence, and follow your incident-response plan for containment, eradication, and recovery. Review whether credentials, files, or other sensitive data may have been accessed. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether any associated accounts appear in public breach corpora, then force password resets and enable multi-factor authentication where relevant.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedRARLAB · WinRAR
WeaknessCWE-351
Added to CISA KEVAug 24, 2023
Federal patch deadlineSep 14, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities