Description WinRar是非常流行的压缩/解压工具。 在显示诊断错误消息通知用户UUE/XXE编码文件中存在无效的文件名时存在格式串漏洞,导致在解码恶意的UUE/XXE文件时会执行任意代码。
References https://www.exploit-db.com/shellcodes/26342 https://app.opencve.io/cve/?product=winrar&vendor=rarlab https://cve.scap.org.cn/vulnerabilities?page=17576 https://cve.imfht.com/detail/CVE-2005-2469
Related VulnerabilitiesWinRAR路径穿越漏洞(CVE-2025-8088)(CVE-2025-8088) WinRAR Windows版本路径遍历漏洞可导致任意代码执行RARLAB WinRAR 文件扩展名欺骗漏洞RALAB WinRAR Recovery Volume 越界写入漏洞RARLAB WinRAR ZIP File 越界读取漏洞