Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2mpw-8427-rgcw

Опубликовано: 03 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed.

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed.

EPSS

Процентиль: 66%
0.01233
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-356

Связанные уязвимости

CVSS3: 6.8
nvd
больше 1 года назад

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed.

CVSS3: 6.8
fstec
больше 1 года назад

Уязвимость механизма Mark of the Web (MOTW) файлового архиватора WinRAR, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 66%
0.01233
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-356