Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse file with a name similar to an extensionless filename that was selected by the user.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WinRAR 权限许可和访问控制漏洞
Vulnerability Description
WinRAR是软件开发者Alexander Roshal所研发的一款文件压缩管理器,它支持RAR与ZIP压缩文件,并且能解压缩CAB、ARJ和LZH等文件。 WinRAR 5.30 beta 4及之前版本的file-execution功能中存在安全漏洞。本地攻击者可借助与无扩展的文件名相同的Trojan horse文件利用该漏洞获取权限。
CVSS Information
N/A
Vulnerability Type
N/A