CVE-2015-5663: High severity winrar vulnerability
Published Dec 30, 2015
·Updated
The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse file with a name similar to an extensionless filename that was selected by the user.
Affected Software
2 affected components
RARLAB WinRAR<=5.30
RARLAB WinRAR<=5.30
Event History
Dec 30, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5663?
CVE-2015-5663 is considered a high-severity vulnerability due to its potential to allow local users to gain elevated privileges.
2
How do I fix CVE-2015-5663?
To fix CVE-2015-5663, upgrade WinRAR to version 5.30 beta 5 or later.
3
Who is affected by CVE-2015-5663?
CVE-2015-5663 affects users of WinRAR versions prior to 5.30 beta 5 on both x86 and x64 platforms.
4
What type of vulnerability is CVE-2015-5663?
CVE-2015-5663 is a local privilege escalation vulnerability related to file-execution functionality.
5
Can CVE-2015-5663 be exploited remotely?
CVE-2015-5663 is not a remote vulnerability; it requires local user access to exploit.