CVE-2022-30333: RARLAB UnRAR
EPSS99.2%No. 207 of 1739 in KEV
CVE year2022listed the same year
Same vendor in KEV5
Same product1
| Field | Value |
|---|---|
| Vendor | RARLAB |
| Product | UnRAR |
| Name | RARLAB UnRAR Directory Traversal Vulnerability |
| Added to KEV | 2022-08-09 |
| US federal due date | 2022-08-30 |
| Ransomware use | Known |
| CWE | CWE-22, CWE-59 |
CISA description
RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A RARLAB UnRAR vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2022-08-09.