Lucene search

K
githubexploit314D4191-9ADF-5061-BBF6-BDBC99189030
HistoryJun 17, 2024 - 7:30 a.m.

Exploit for Insufficient Type Distinction in Rarlab Winrar

2024-06-1707:30:47
144
winrar
vulnerability
exploit
version 6.23
deception
file extension
logic vulnerability
rarlab
winrar.exe
test poc
python code
detailed explanation

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0.408

Percentile

97.3%

💥 WinRAR 漏洞说明(CVE-2023-38831)

> 在WinRAR版本6.23之前存在可欺骗文件扩展名漏洞,…

This is an article that belongs to githubexploit private collection.
Please sign in to get more Information.

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0.408

Percentile

97.3%