vendor:
WinRAR
by:
posidron and muts
9,3
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: WinRAR
Affected Version From: 3.60 beta 4
Affected Version To: 3.60 beta 4
Patch Exists: YES
Related CWE: CVE-2009-1330
CPE: a:winrar:winrar
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
WinRAR – Stack Overflows in SelF – eXtracting Archives
This exploit is a stack overflow vulnerability in WinRAR 3.60 beta 4. It allows an attacker to execute arbitrary code by creating a malicious SFX archive. The malicious SFX archive contains a comment.txt file which contains the malicious code and a sample.exe file which contains the shellcode. When the SFX archive is opened, the malicious code is executed.
Mitigation:
Upgrade to the latest version of WinRAR.