Impact
An unvalidated path input in the unrar.dll component of IZArc 4.6 allows a path traversal attack. This weakness, identified as CWE‑35, can enable an attacker to read or write files outside the intended extraction directory, and in some contexts could facilitate execution of malicious payloads, undermining confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects the IZArc archiver, specifically version 4.6, and targets the unrar.dll component. Organizations should confirm whether this component is present in their deployed installations and whether the affected version is in use.
Risk and Exploitability
The EPSS score of <1% indicates a low probability of exploitation in the current dataset, but the CVSS score of 7.8 demonstrates a high severity. The CVE is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. The likely attack vector involves delivering a crafted archive that the unrar.dll component processes, enabling path traversal to access arbitrary files. This inference is based on the description of a path traversal flaw and a typical attack scenario for such weaknesses.
OpenCVE Enrichment