← CVE Tracker
7.5HIGHCISA KEV — actively exploited

CVE-2022-30333 — RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract…

Rarlab · Unrar · Published 9 May 2022 · Modified 2 Oct 2026

Description

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

References

What to do
  1. Check whether Unrar is in your asset inventory.
  2. Exploitation confirmed — patch within 72 hours.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2022-30333