vendor:
WinRAR
by:
Unknown
9.8
CVSS
CRITICAL
Remote Code Execution
94
CWE
Product Name: WinRAR
Affected Version From: All versions prior to the patched version
Affected Version To: Patched version
Patch Exists: YES
Related CWE: CVE-2020-XXXX
CPE: a:rarlab:winrar
Platforms Tested: Windows
2020
RAR Archive Remote Code Execution
This exploit allows an attacker to execute arbitrary code on a victim's machine by creating a specially crafted RAR archive file. By manipulating the right_hdr_crc value in the RAR file header, the attacker can modify the file content to include malicious code. When the victim opens the RAR file, the malicious code is executed.
Mitigation:
The vendor has released a patch for this vulnerability. Users are advised to update their RAR software to the latest version.