RARLAB WinRAR
cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*
- >= 7.10, < 7.11
This vulnerability is being actively exploited in the wild.
A directory traversal vulnerability allowing remote code execution has been identified in RARLAB WinRAR. This issue arises from improper handling of file paths within archive files, enabling an attacker to craft a file path that traverses to unintended directories. Exploitation requires user interaction, as the target must open a malicious file or visit a harmful webpage. The vulnerability affects WinRAR versions prior to 7.11.
Exploitation of this vulnerability allows for arbitrary code execution on the affected system, executed in the context of the user.
RARLAB has released a patch for this vulnerability in WinRAR version 7.11. Users are advised to update to this version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.