Description
Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9627 | Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed. |
References
History
Tue, 01 Jul 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rarlab
Rarlab winrar |
|
| CPEs | cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rarlab
Rarlab winrar |
Thu, 03 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Apr 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed. | |
| Weaknesses | CWE-356 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-04-03T13:52:45.659Z
Reserved: 2025-03-27T23:41:26.316Z
Link: CVE-2025-31334
Updated: 2025-04-03T13:52:37.368Z
Status : Analyzed
Published: 2025-04-03T06:15:42.903
Modified: 2025-07-01T15:10:55.773
Link: CVE-2025-31334
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD