CVE-2014-125119: WinRAR < 5.00 Filename Spoofing RCE
A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to inconsistencies between the Central Directory and Local File Header entries in ZIP files. When viewed in WinRAR, the file name from the Central Directory is displayed to the user, while the file from the Local File Header is extracted and executed. An attacker can leverage this flaw to spoof filenames and trick users into executing malicious payloads under the guise of harmless files, potentially leading to remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-125119?
CVE-2014-125119 is classified as a moderate severity vulnerability due to its potential to cause filename spoofing issues.
How do I fix CVE-2014-125119?
To fix CVE-2014-125119, update to a patched version of WinRAR that eliminates the filename spoofing issue.
What versions of WinRAR are affected by CVE-2014-125119?
CVE-2014-125119 affects WinRAR versions prior to 5.00.
What type of vulnerability is CVE-2014-125119?
CVE-2014-125119 is a filename spoofing vulnerability that arises from inconsistencies in ZIP archive entry headers.
What impact does CVE-2014-125119 have on user security?
CVE-2014-125119 can lead to misleading file names, potentially tricking users into executing malicious files.