Vulnerability threat dossier

CVE-2023-38831

rarlabwinrar

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.

VTP deterministic threat62.5of 100 · CVSS excluded

VTP analyst assessment

WinRAR archive-viewing code execution

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence90%
Public exploitation · VTP factKEV

Assessment

CISA KEV lists this WinRAR flaw as known exploited and records known ransomware campaign use. A crafted ZIP pairs a benign-looking file with a same-named folder containing executable content; viewing the benign file can execute code.

Why it matters

  • The delivery path relies on a user opening an archive and viewing its contents.
  • Successful execution can give an attacker code execution on the user's system.

Evidence

2 record references and 3 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

A recent press roundup labels the issue a zero-day, but its excerpt does not add campaign details.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use WinRAR before 6.23, update it or remove it from managed endpoints.

AI baseline history (2)
  1. BASELINE ASSESSED
    WinRAR archive-viewing code executiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    WinRAR archive code executiongpt-5.6-sol · high
Technical severityHIGHCVSS 7.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence64%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 1.00; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

1publications detected
1underlying evidence chains

0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
64%claim confidence
UNKNOWNreport:73d2723bf9f3506966790e3904c98c1f2c69cabde73f0d4bf62031ee77cb4b0dACTIVE
Evidence
04

Event history

Threat timeline

  1. 17:5224 Sept
    ZERO DAY

    Zero Day

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 00:0024 Aug
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts look real enough. And some attacks barely need an exploit at all — just

CVE-2023-38831CVE-2024-21412
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score62.5vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction19.96 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency10 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE
CWE-345, CWE-351
CPE records
1
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.