logo

Government-backed actors exploiting WinRAR vulnerability

ID: 475f7718-bbe1-5af8-9da9-8ece8dd1ad51

STIX ID: report--475f7718-bbe1-5af8-9da9-8ece8dd1ad51

Feed Name: Google's Threat Analysis Group (TAG)

Threat Score
75/100

Date Published: 2023-10-18

Date Updated: 2026-04-27

Author: Kate Morgan

...
...

This report details CVE-2023-3883: WinRAR normalizes paths by removing trailing spaces but calls ShellExecuteExW with the non-normalized path containing a trailing space, causing ShellExecute to fail extension detection and call shell32!ApplyDefaultExts. ApplyDefaultExts enumerates files in the directory and executes the first file matching hardcoded executable extensions (.pif, .com, .exe, .bat, .lnk, .cmd), so a crafted archive entry with a space in the extension can result in arbitrary code execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.