CVE-2024-36052: High severity winrar vulnerability
Published May 21, 2024
·Updated
RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899.
Affected Software
3 affected components
RARLAB WinRAR<7.00
All of the following
RARLAB WinRAR<7.00
Microsoft Windows
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 21, 2024
CVE Published
via NVD·05:15 PM
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 20, 2024
Data Sourced
via MITRE·02:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-36052?
CVE-2024-36052 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-36052?
To fix CVE-2024-36052, upgrade to WinRAR version 7.00 or later.
3
What does CVE-2024-36052 exploit?
CVE-2024-36052 exploits ANSI escape sequences to spoof screen output on Windows systems.
4
Is CVE-2024-36052 a denial of service vulnerability?
No, CVE-2024-36052 is not a denial of service vulnerability, but rather a screen output spoofing issue.
5
Which versions of WinRAR are affected by CVE-2024-36052?
WinRAR versions before 7.00 are affected by CVE-2024-36052.