U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-30370

Change History

New CVE Received from Zero Day Initiative 4/02/2024 5:15:50 PM

Action Type Old Value New Value
Added Description

								
							
							
						
RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The-Web protection mechanism on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must perform a specific action on a malicious page.

The specific flaw exists within the archive extraction functionality. A crafted archive entry can cause the creation of an arbitrary file without the Mark-Of-The-Web. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current user. Was ZDI-CAN-23156.
Added CVSS V3

								
							
							
						
Zero Day Initiative AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Added CWE

								
							
							
						
Zero Day Initiative CWE-693
Added Reference

								
							
							
						
Zero Day Initiative https://www.rarlab.com/rarnew.htm#27.%20Busgs%20fixed [No types assigned]
Added Reference

								
							
							
						
Zero Day Initiative https://www.zerodayinitiative.com/advisories/ZDI-24-357/ [No types assigned]