216.73.216.233

CVE-2025-31334

· Published 03/04/2025 06:15 · Modified 03/04/2025 06:15

Labels: CVE-2025-31334 2025-04-03CVE-2025-31334CWE-356[email protected]

Essential information

Published
03/04/2025 06:15
Modified
03/04/2025 06:15
Author
Creator
CVSS
6.8 MEDIUM (v3.0)
CISA KEV
No
CWE
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
winrar / winrar cpe:2.3:a:winrar:winrar:<7.11:*:*:*:*:*:*:*

References