Skip to content
appaloosa scout logo main rounded
HIGH 7.4

CVE-2015-5663

The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse file with a name similar to an extensionless filename that was selected by the user.

CVSS v3 CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS 0.1% percentile 23.9%

Affected tracked apps

Vulnerable CPE configurations

Vendor Product Platform Versions CPE 2.3 URI
rarlab winrar Windows ≤5.30 cpe:2.3:a:rarlab:winrar:*:beta_4:*:*:*:*:x64:*
rarlab winrar Windows ≤5.30 cpe:2.3:a:rarlab:winrar:*:beta_4:*:*:*:*:x86:*
View on NVD ↗