
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2019-25677 is a denial of service (DoS) vulnerability in WinRAR 5.61 (32-bit) that allows a local attacker to crash the application by placing a malformed winrar.lng language file in the installation directory. The vulnerability was formally published to the CVE database and GitHub Advisory Database on April 5, 2026, though the underlying issue was discovered in 2019 (Exploit-DB entry 46432). It affects WinRAR versions up to and including 5.61 on x86 platforms. The CVSS v3.1 base score is 5.5 (Medium), while the CVSS v4.0 base score is 6.9 (Medium) (GitHub Advisory, VulnCheck).
The root cause is classified under CWE-379 (Creation of Temporary File in Directory with Insecure Permissions), reflecting improper handling of externally supplied language files without adequate validation. When a malformed winrar.lng file is placed in the WinRAR installation directory, the application reads invalid data from it during archive testing operations, triggering an access violation at memory address 004F1DB8. Exploitation requires local access and the ability to write to the installation directory; the crash is triggered when a user opens an archive and clicks the "Test" button. A public proof-of-concept is available on Exploit-DB (Exploit-DB, GitHub Advisory).
Successful exploitation results in a crash of the WinRAR application, causing a denial of service for the affected user. The impact is limited to availability — there is no confidentiality or integrity impact, and the crash does not affect subsequent systems or enable lateral movement. Users are unable to perform archive testing operations until the application is restarted, and no data exfiltration or code execution has been demonstrated (GitHub Advisory, VulnCheck).
A proof-of-concept exploit has been publicly available on Exploit-DB (entry 46432) since 2019, though Feedly's analysis classifies the listed exploit URL as non-exploitable based on available metadata. There is no confirmed evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.012–0.016%, placing it in the 4th percentile for exploitation likelihood (GitHub Advisory, Exploit-DB).
C:\Program Files\WinRAR\ or C:\Program Files (x86)\WinRAR\).winrar.lng file containing invalid or corrupted data that will cause an access violation when parsed by WinRAR 5.61.winrar.lng into the WinRAR installation directory, replacing or supplementing the legitimate language file.004F1DB8 (Exploit-DB, GitHub Advisory).winrar.lng file in the WinRAR installation directory (e.g., C:\Program Files\WinRAR\winrar.lng) with an unusual file size, modification timestamp, or content inconsistent with the installed WinRAR version.004F1DB8.winrar.exe) terminating unexpectedly with an access violation exception shortly after a user initiates an archive test operation.Users should update WinRAR to a version newer than 5.61, as later releases address this issue (VulnCheck). As a workaround, restrict write access to the WinRAR installation directory to prevent unauthorized placement or modification of language files. Additionally, monitor the installation directory for unexpected changes to winrar.lng or other configuration files.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."