Security Research

CVE-2023-38831 WinRAR Spoof: 0-Click Attack via Archive File Masquerading

#Vulnerability Analysis#Code Audit#Malware
Copper-orange RAR archive triggering a hidden executable on extraction

WinRAR’s extraction logic has a hidden behavior — when an archive contains both a “same-named directory” and a “same-named executable file,” WinRAR prefers to extract the executable file to the current directory and auto-execute it. An attacker’s carefully crafted “looks-like-a-safe-image” turns out to be an executable.

Unlock to view this content.