CVE-2019-25677
WinRAR vulnerability analysis and mitigation

Overview

CVE-2019-25677 is a denial of service (DoS) vulnerability in WinRAR 5.61 (32-bit) that allows a local attacker to crash the application by placing a malformed winrar.lng language file in the installation directory. The vulnerability was formally published to the CVE database and GitHub Advisory Database on April 5, 2026, though the underlying issue was discovered in 2019 (Exploit-DB entry 46432). It affects WinRAR versions up to and including 5.61 on x86 platforms. The CVSS v3.1 base score is 5.5 (Medium), while the CVSS v4.0 base score is 6.9 (Medium) (GitHub Advisory, VulnCheck).

Technical details

The root cause is classified under CWE-379 (Creation of Temporary File in Directory with Insecure Permissions), reflecting improper handling of externally supplied language files without adequate validation. When a malformed winrar.lng file is placed in the WinRAR installation directory, the application reads invalid data from it during archive testing operations, triggering an access violation at memory address 004F1DB8. Exploitation requires local access and the ability to write to the installation directory; the crash is triggered when a user opens an archive and clicks the "Test" button. A public proof-of-concept is available on Exploit-DB (Exploit-DB, GitHub Advisory).

Impact

Successful exploitation results in a crash of the WinRAR application, causing a denial of service for the affected user. The impact is limited to availability — there is no confidentiality or integrity impact, and the crash does not affect subsequent systems or enable lateral movement. Users are unable to perform archive testing operations until the application is restarted, and no data exfiltration or code execution has been demonstrated (GitHub Advisory, VulnCheck).

Exploitability

A proof-of-concept exploit has been publicly available on Exploit-DB (entry 46432) since 2019, though Feedly's analysis classifies the listed exploit URL as non-exploitable based on available metadata. There is no confirmed evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.012–0.016%, placing it in the 4th percentile for exploitation likelihood (GitHub Advisory, Exploit-DB).

Exploitation steps

  1. Gain local access: Obtain a local user account on the target Windows system with write permissions to the WinRAR installation directory (typically C:\Program Files\WinRAR\ or C:\Program Files (x86)\WinRAR\).
  2. Craft malformed language file: Create or obtain a malformed winrar.lng file containing invalid or corrupted data that will cause an access violation when parsed by WinRAR 5.61.
  3. Place the file: Copy the malformed winrar.lng into the WinRAR installation directory, replacing or supplementing the legitimate language file.
  4. Trigger the crash: Wait for or instruct a user to open any archive in WinRAR and click the "Test" button, which causes the application to read the malformed language file and crash with an access violation at memory address 004F1DB8 (Exploit-DB, GitHub Advisory).

Indicators of compromise

  • File System: Presence of an unexpected or modified winrar.lng file in the WinRAR installation directory (e.g., C:\Program Files\WinRAR\winrar.lng) with an unusual file size, modification timestamp, or content inconsistent with the installed WinRAR version.
  • Logs: Windows Event Logs (Application) showing a WinRAR application crash (Event ID 1000) with a faulting module or address referencing 004F1DB8.
  • Process: WinRAR process (winrar.exe) terminating unexpectedly with an access violation exception shortly after a user initiates an archive test operation.

Mitigation and workarounds

Users should update WinRAR to a version newer than 5.61, as later releases address this issue (VulnCheck). As a workaround, restrict write access to the WinRAR installation directory to prevent unauthorized placement or modification of language files. Additionally, monitor the installation directory for unexpected changes to winrar.lng or other configuration files.

Additional resources


SourceThis report was generated using AI

Related WinRAR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-8088HIGH8.4
  • Clam AntiVirus logoClam AntiVirus
  • clamav
YesYesAug 08, 2025
CVE-2026-14191HIGH7.8
  • WinRAR logoWinRAR
  • cpe:2.3:a:rarlab:winrar
NoYesJul 01, 2026
CVE-2019-25677MEDIUM6.9
  • WinRAR logoWinRAR
  • cpe:2.3:a:rarlab:winrar
NoYesApr 05, 2026
CVE-2025-52331MEDIUM6.1
  • WinRAR logoWinRAR
  • unrar-nonfree
NoYesNov 12, 2025
CVE-2025-14111LOW1.3
  • WinRAR logoWinRAR
  • rar
NoNoDec 05, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management