vendor:
WinRAR
by:
chr1x, juan vazquez
7.5
CVSS
HIGH
Filename Spoofing
601
CWE
Product Name: WinRAR
Affected Version From: Not mentioned
Affected Version To: Not mentioned
Patch Exists: YES
Related CWE:
CPE: a:rarlab:winrar
Platforms Tested: Windows
2009
WinRAR Filename Spoofing
This module abuses a filename spoofing vulnerability in WinRAR. The vulnerability exists when opening ZIP files. The file names showed in WinRAR when opening a ZIP file come from the central directory, but the file names used to extract and open contents come from the Local File Header. This inconsistency allows to spoof file names when opening ZIP files with WinRAR, which can be abused to execute arbitrary code, as exploited in the wild in March 2014.
Mitigation:
Update WinRAR to the latest version to fix the filename spoofing vulnerability.