CVE-2024-33899
WinRAR vulnerability analysis and mitigation

Overview

RARLAB WinRAR before version 7.00, on Linux and UNIX platforms, contains an ANSI escape sequence injection vulnerability that allows attackers to spoof screen output or cause denial of service. The vulnerability, discovered by security researcher Siddharth Dushantha and disclosed on February 28, 2024, affects the console versions of RAR and UnRAR in versions 6.24 and earlier. It's important to note that the GUI version of WinRAR and the UnRAR library were not impacted by this vulnerability (Medium Blog, SecurityOnline).

Technical details

The vulnerability leverages ANSI escape sequences, which are special codes used to control text formatting, colors, and cursor positioning in terminals. The issue stems from WinRAR's failure to filter ANSI escape sequences in the archive comment section, allowing attackers to inject malicious ANSI codes. The vulnerability has been assigned a CVSS v3.1 Base Score of 7.1 (HIGH) with the vector string CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H. The weakness is classified as CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences (NVD).

Impact

The vulnerability can be exploited in two primary ways: attackers can spoof file listings by injecting malicious ANSI codes into archive comments, potentially tricking users into opening harmful files disguised as harmless ones, and on Linux and Unix systems, specific ANSI sequences can trigger a local denial-of-service condition, rendering the terminal unusable. The impact is more severe on Linux and Unix systems due to the potential for denial-of-service attacks (SecurityOnline).

Exploitability

A proof-of-concept exploit has been demonstrated where attackers can hide malicious files (e.g., virus.exe) within an archive and replace their names in the file listing with seemingly harmless ones (e.g., notvirus.pdf). The vulnerability can be triggered by injecting ANSI escape sequences into archive comments, which are then processed when listing the contents of the archive using unrar l command (Medium Blog).

Mitigation and workarounds

RARLAB has addressed this vulnerability in WinRAR version 7.00. The fix includes filtering out character 27 from screen output, which is used to declare ANSI escape control sequences in terminal applications. Users are strongly advised to update their software to version 7.00 or later to protect against potential attacks (RARLAB).

Additional resources


SourceThis report was generated using AI

Related WinRAR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-8088HIGH8.4
  • Clam AntiVirus logoClam AntiVirus
  • clamav
YesYesAug 08, 2025
CVE-2026-14191HIGH7.8
  • WinRAR logoWinRAR
  • cpe:2.3:a:rarlab:winrar
NoYesJul 01, 2026
CVE-2019-25677MEDIUM6.9
  • WinRAR logoWinRAR
  • cpe:2.3:a:rarlab:winrar
NoYesApr 05, 2026
CVE-2025-52331MEDIUM6.1
  • WinRAR logoWinRAR
  • unrar-nonfree
NoYesNov 12, 2025
CVE-2025-14111LOW1.3
  • WinRAR logoWinRAR
  • rar
NoNoDec 05, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management