CVE-2023-38831
Confirmed PUBLISHEDRARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue...
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.
- CVE Published
- Aug 23, 2023
- Exploitation Reported
- Aug 24, 2023
- CVSS
- 7.8 High
- EPSS
- —
Affected Versions
| Vendor | Product | Version | Status |
|---|---|---|---|
| rarlab |
winrar
|
0 to < 6.23 |
Affected |
| n/a |
n/a
|
n/a |
Affected |
CVE References
- group-ib.com/blog/cve-2023-38831-winrar-zero-day group-ib.com · CVE Record https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/
- bleepingcomputer.com/news/security/winrar-zero-day-exploited-sinc... bleepingcomputer.com · CVE Record https://www.bleepingcomputer.com/news/security/winrar-zero-day-exploi...
- news.ycombinator.com/item news.ycombinator.com · CVE Record https://news.ycombinator.com/item?id=37236100
- packetstormsecurity.com/files/174573/WinRAR-Remote-Code-Execution.html packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/174573/WinRAR-Remote-Code-Execut...
- blog.google/threat-analysis-group/government-backed-acto... blog.google · CVE Record https://blog.google/threat-analysis-group/government-backed-actors-ex...
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2023-08-24 00:00 UTC |
Scanner Artifacts
Nuclei and Metasploit references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/winrar_cve_2023_38831.rb | Apr 28, 2025 |
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Status
Exploited in the wild
Recorded 2023-08-24 00:00:00 UTC · CISA
Used in malware
Recorded 2023-08-24 00:00:00 UTC · CISA
Proof of concept available
Recorded 2023-08-24 16:03:07 UTC · GitHub
Weaknesses (CWE)
-
Insufficient Type Distinction
Scanner Integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/winrar_cve_2023_38831.rb | Apr 28, 2025 |
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2024-04-06 16:55:29 UTC · 0 stars
github · Created 2023-10-21 17:03:48 UTC · 0 stars
github · Created 2023-09-21 06:08:30 UTC · 3 stars
Proof-of-Concept (POC) of CVE-2023-38831 Zero-Day vulnerability in WinRAR
github · Created 2023-09-17 05:21:30 UTC · 0 stars
github · Created 2023-09-12 16:01:17 UTC · 3 stars
Proof of concept (PoC) exploit for WinRAR vulnerability (CVE-2023-38831) vulnerability
github · Created 2023-09-12 14:07:00 UTC · 9 stars
CVE-2023-38831 WinRaR Exploit Generator
github · Created 2023-09-03 21:14:05 UTC · 12 stars
This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is executed, leading to code execution.
github · Created 2023-09-01 16:45:42 UTC · 3 stars
CVE-2023-38831 winrar exploit builder
github · Created 2023-08-30 19:55:11 UTC · 8 stars
This is a POC for the CVE-2023-3883 exploit targeting WinRAR up to 6.22. Modified some existing internet-sourced POCs by introducing greater dynamism and incorporated additional try-except blocks within the code.
github · Created 2023-08-30 11:52:23 UTC · 5 stars
Proof-of-Concept for CVE-2023-38831 Zero-Day vulnerability in WinRAR
github · Created 2023-08-28 22:08:31 UTC · 11 stars
CVE-2023-38831 winrar exploit generator and get reverse shell
github · Created 2023-08-28 15:26:14 UTC · 4 stars
KQL Hunting for WinRAR CVE-2023-38831
github · Created 2023-08-28 14:48:22 UTC · 41 stars
Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)
github · Created 2023-08-28 08:56:16 UTC · 22 stars
Pasos necesarios para obtener una reverse shell explotando la vulnerabilidad de winrar CVE-2023-38831 en versiones anteriores a 6.23.
github · Created 2023-08-28 04:56:10 UTC · 71 stars
CVE-2023-38831 PoC (Proof Of Concept)
github · Created 2023-08-27 21:49:37 UTC · 115 stars
An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831, WinRAR RCE before versions 6.23
github · Created 2023-08-27 08:42:24 UTC · 2 stars
github · Created 2023-08-25 09:44:08 UTC · 788 stars
CVE-2023-38831 winrar exploit generator
github · Created 2023-08-24 16:03:07 UTC · 91 stars
lazy way to create CVE-2023-38831 winrar file for testing
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
15:02 UTC about 1 year ago15:02 UTC · about 1 year ago
Metasploit module available
Exploit module available
-
16:03 UTC almost 3 years ago16:03 UTC · almost 3 years ago
Public PoC available
Public proof-of-concept code published
-
00:00 UTC almost 3 years ago00:00 UTC · almost 3 years ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
00:00 UTC almost 3 years ago00:00 UTC · almost 3 years ago
First public exploitation report
Exploit observed in malware
-
00:00 UTC almost 3 years ago00:00 UTC · almost 3 years ago
CVE published
Vulnerability disclosed publicly
-
00:00 UTC almost 3 years ago00:00 UTC · almost 3 years ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2023-38831
{
"cve_id": "CVE-2023-38831",
"title": "RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a u...",
"affected_vendor": "RARLAB",
"affected_product": "WinRAR",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 7.8,
"epss_score": null,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}