Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2024-30370
Description:RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The-Web protection mechanism on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must perform a specific action on a malicious page. The specific flaw exists within the archive extraction functionality. A crafted archive entry can cause the creation of an arbitrary file without the Mark-Of- The-Web. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current user. Was ZDI-CAN-23156.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2024-30370
ZDI-24-357
https://www.zerodayinitiative.com/advisories/ZDI-24-357/
vendor-provided URL
https://www.rarlab.com/rarnew.htm#27.%20Busgs%20fixed




© 1998-2025 E-Soft Inc. All rights reserved.