Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2022-43650

HIGH 7.1

This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR 6.11.0.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ZIP files. Crafted data in a ZIP file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-19232.

Attack vector : Local No privileges required
Show raw CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
EPSS 23.04% moderate exploit risk percentile 97.5%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • WinRAR Windows winget:RARLab.WinRAR
    Affected Fixed in Latest tracked 7.23.0 undetermined
Vulnerable CPE configurations (1)
Vendor Product Versions
rarlab winrar
All platforms (wildcard)
View on NVD ↗