CVE-2025-31334: Medium severity winrar vulnerability
Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31334?
CVE-2025-31334 has a severity rating that indicates it allows for arbitrary code execution from crafted symbolic links.
How do I fix CVE-2025-31334?
To fix CVE-2025-31334, upgrade WinRAR to version 7.11 or later.
What versions of WinRAR are affected by CVE-2025-31334?
WinRAR versions prior to 7.11 are affected by CVE-2025-31334.
What type of attack is possible with CVE-2025-31334?
CVE-2025-31334 allows an attacker to execute arbitrary code through specially crafted symbolic links.
Is it safe to open symbolic links in WinRAR prior to version 7.11?
No, it is not safe to open symbolic links in WinRAR versions prior to 7.11 due to the vulnerability in CVE-2025-31334.