Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2mpw-8427-rgcw

Опубликовано: 03 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed.

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed.

EPSS

Процентиль: 59%
0.00389
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-356

Связанные уязвимости

CVSS3: 6.8
nvd
10 месяцев назад

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed.

CVSS3: 6.8
fstec
11 месяцев назад

Уязвимость механизма Mark of the Web (MOTW) файлового архиватора WinRAR, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 59%
0.00389
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-356