Information Disclosure Vulnerability in WinRAR by RARLAB
CVE-2022-43650

2.5LOW

Key Information:

Vendor

Rarlab

Status
Vendor
CVE Published:
29 March 2023

What is CVE-2022-43650?

This vulnerability in WinRAR allows remote attackers to disclose sensitive information by exploiting a flaw in ZIP file parsing. User interaction is necessary, as the target must open a malicious ZIP file or visit a malicious webpage. Attackers can leverage crafted data within ZIP files, potentially leading to a read past the end of an allocated buffer. This flaw opens opportunities for attackers to combine it with other vulnerabilities to execute arbitrary code within the context of the affected process.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WinRAR 6.11.0.0

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bakker
.