vendor:
WinRar
by:
R-73eN
7.5
CVSS
HIGH
Command Execution
CWE
Product Name: WinRar
Affected Version From: WinRAR 5.21
Affected Version To: WinRAR 5.21
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP3
2015
WinRar SFX OLE Command Execution
The WinRar SFX OLE Command Execution vulnerability allows an attacker to execute arbitrary commands on a Windows system by creating a specially crafted SFX archive. By tricking a user into opening the archive, the attacker can run arbitrary code with the same privileges as the user.
Mitigation:
Update to the latest version of WinRar, as this vulnerability has been patched in later versions.