{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2023-38831",
  "revision": 1,
  "title": "WinRAR — the file you opened was not the file that ran",
  "summary": "An archive can carry a harmless-looking file and a folder with the same name, and WinRAR before 6.23 runs what is inside the folder when the user opens the file they meant to look at. Exploited from April to October 2023.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.8,
    "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.98022,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2023-08-24",
    "prerequisites": "The user must open a file inside an archive the attacker supplied."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "WinRAR >= 6.23"
    ]
  },
  "mitre_attack": [
    "T1204.002"
  ],
  "kill_chain": "execution",
  "recommended_action": "Update WinRAR to 6.23 or later on every desktop. The lure is a file the user chose to open, so nothing about it looks like an attachment to distrust.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-38831",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2023-38831",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-38831",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38831",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "exploit",
      "url": "http://packetstormsecurity.com/files/174573/WinRAR-Remote-Code-Execution.html"
    },
    {
      "type": "exploit",
      "url": "https://blog.google/threat-analysis-group/government-backed-actors-exploiting-winrar-vulnerability/"
    },
    {
      "type": "exploit",
      "url": "https://www.bleepingcomputer.com/news/security/winrar-zero-day-exploited-since-april-to-hack-trading-accounts/"
    }
  ],
  "published_at": "2023-08-23T17:15:43.863Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "winrar",
    "rarlab",
    "archive",
    "spoofing",
    "ransomware",
    "kev"
  ]
}
