CVE-2022-30333
RARLAB UnRAR Directory Traversal Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 30 August 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 99.09% probability · 100th percentile
- CISA KEV
- Listed 9 August 2022 · due 30 August 2022 · used in ransomware campaigns
- Weakness
- CWE-22, CWE-59
- Affected
- rarlab/unrar · debian/debian linux
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. Vulnerability updated with version 6.12. Accessing link will download update information: https://www.rarlab.com/rar/rarlinux-x32-612.tar.gz; https://nvd.nist.gov/vuln/detail/CVE-2022-30333
References
- http://packetstormsecurity.com/files/167989/Zimbra-UnRAR-Path-Traversal.htmlExploit, Third Party Advisory, VDB Entry
- https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00022.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202309-04Third Party Advisory
- https://www.rarlab.com/rar/rarlinux-x32-612.tar.gzPatch
- https://www.rarlab.com/rar_add.htmProduct
- http://packetstormsecurity.com/files/167989/Zimbra-UnRAR-Path-Traversal.htmlExploit, Third Party Advisory, VDB Entry
- https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00022.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202309-04Third Party Advisory
- https://www.rarlab.com/rar/rarlinux-x32-612.tar.gzPatch
- https://www.rarlab.com/rar_add.htmProduct
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-30333US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.