Government-backed actors exploiting WinRAR vulnerability
ID: 475f7718-bbe1-5af8-9da9-8ece8dd1ad51
STIX ID: report--475f7718-bbe1-5af8-9da9-8ece8dd1ad51
Feed Name: Google's Threat Analysis Group (TAG)
This report details CVE-2023-3883: WinRAR normalizes paths by removing trailing spaces but calls ShellExecuteExW with the non-normalized path containing a trailing space, causing ShellExecute to fail extension detection and call shell32!ApplyDefaultExts. ApplyDefaultExts enumerates files in the directory and executes the first file matching hardcoded executable extensions (.pif, .com, .exe, .bat, .lnk, .cmd), so a crafted archive entry with a space in the extension can result in arbitrary code execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
