RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.
CVE-2023-38831
Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2023-08-24), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 7.8 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 7.8
- EG Score
- 9.0(high)
- EPSS
- 99.9%
- KEV
- ⚠ Exploited
Published
August 23, 2023
Last Modified
October 31, 2025
Advisory Details (4)
Auto-updated Jun 4, 2026CVE-2023-38831 zero-Day vulnerability in WinRAR | Group-IB Blog
https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/WinRAR zero-day exploited since April to hack trading accounts
https://www.bleepingcomputer.com/news/security/winrar-zero-day-exploited-since-april-to-hack-trading-accounts/Government-backed actors exploiting WinRAR vulnerability
https://blog.google/threat-analysis-group/government-backed-actors-exploiting-winrar-vulnerability/Weakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 46× in last 7d / 190× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 349 total refreshes for this CVE.
- 2026-07-22 21:38 UTCEG score recompute
- 2026-07-22 21:38 UTCGHSA enrichment
- 2026-07-22 19:40 UTCCISA KEV update
- 2026-07-22 17:11 UTCGHSA enrichment
- 2026-07-22 12:48 UTCGHSA enrichment
- 2026-07-22 08:27 UTCGHSA enrichment
- 2026-07-22 04:05 UTCGHSA enrichment
- 2026-07-21 23:42 UTCGHSA enrichment
- 2026-07-21 17:39 UTCGHSA enrichment
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-21 13:16 UTCGHSA enrichment
- 2026-07-21 08:53 UTCGHSA enrichment
- 2026-07-21 04:32 UTCGHSA enrichment
- 2026-07-21 00:09 UTCGHSA enrichment
- 2026-07-20 19:48 UTCGHSA enrichment
- 2026-07-20 15:26 UTCGHSA enrichment
- 2026-07-20 11:02 UTCGHSA enrichment
- 2026-07-20 06:40 UTCGHSA enrichment
- 2026-07-20 01:55 UTCGHSA enrichment
- 2026-07-19 21:33 UTCGHSA enrichment
- 2026-07-19 17:11 UTCGHSA enrichment
- 2026-07-19 12:48 UTCGHSA enrichment
- 2026-07-19 08:27 UTCGHSA enrichment
- 2026-07-19 04:05 UTCGHSA enrichment
- 2026-07-18 23:42 UTCGHSA enrichment
Show 75 moreShow fewer
- 2026-07-18 19:20 UTCGHSA enrichment
- 2026-07-18 14:57 UTCGHSA enrichment
- 2026-07-18 10:35 UTCEG score recompute
- 2026-07-18 10:35 UTCGHSA enrichment
- 2026-07-18 10:03 UTCEPSS rescore
- 2026-07-18 10:03 UTCEPSS rescore
- 2026-07-18 06:13 UTCGHSA enrichment
- 2026-07-18 01:51 UTCGHSA enrichment
- 2026-07-17 21:29 UTCGHSA enrichment
- 2026-07-17 17:07 UTCGHSA enrichment
- 2026-07-17 12:45 UTCGHSA enrichment
- 2026-07-17 08:22 UTCEG score recompute
- 2026-07-17 08:22 UTCGHSA enrichment
- 2026-07-17 04:00 UTCGHSA enrichment
- 2026-07-16 23:38 UTCGHSA enrichment
- 2026-07-16 19:16 UTCGHSA enrichment
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-16 14:52 UTCGHSA enrichment
- 2026-07-16 10:31 UTCGHSA enrichment
- 2026-07-16 06:09 UTCGHSA enrichment
- 2026-07-16 01:46 UTCGHSA enrichment
- 2026-07-15 21:25 UTCGHSA enrichment
- 2026-07-15 17:03 UTCGHSA enrichment
- 2026-07-15 16:49 UTCCISA KEV update
- 2026-07-15 15:04 UTCCISA KEV update
- 2026-07-15 12:40 UTCGHSA enrichment
- 2026-07-15 08:18 UTCGHSA enrichment
- 2026-07-15 03:56 UTCGHSA enrichment
- 2026-07-14 23:35 UTCGHSA enrichment
- 2026-07-14 19:13 UTCGHSA enrichment
- 2026-07-14 18:05 UTCCISA KEV update
- 2026-07-14 14:51 UTCGHSA enrichment
- 2026-07-14 10:29 UTCGHSA enrichment
- 2026-07-14 06:07 UTCGHSA enrichment
- 2026-07-14 01:45 UTCGHSA enrichment
- 2026-07-13 21:23 UTCGHSA enrichment
- 2026-07-13 17:07 UTCCISA KEV update
- 2026-07-13 17:01 UTCGHSA enrichment
- 2026-07-13 12:39 UTCGHSA enrichment
- 2026-07-13 08:16 UTCGHSA enrichment
- 2026-07-13 03:53 UTCGHSA enrichment
- 2026-07-12 23:32 UTCGHSA enrichment
- 2026-07-12 19:10 UTCGHSA enrichment
- 2026-07-12 14:48 UTCGHSA enrichment
- 2026-07-12 10:26 UTCGHSA enrichment
- 2026-07-12 06:04 UTCGHSA enrichment
- 2026-07-12 01:41 UTCGHSA enrichment
- 2026-07-11 21:19 UTCGHSA enrichment
- 2026-07-11 16:58 UTCGHSA enrichment
- 2026-07-11 12:36 UTCGHSA enrichment
- 2026-07-11 08:14 UTCGHSA enrichment
- 2026-07-11 03:52 UTCGHSA enrichment
- 2026-07-10 23:31 UTCGHSA enrichment
- 2026-07-10 19:09 UTCGHSA enrichment
- 2026-07-10 17:52 UTCCISA KEV update
- 2026-07-10 14:47 UTCGHSA enrichment
- 2026-07-10 10:25 UTCGHSA enrichment
- 2026-07-10 06:02 UTCGHSA enrichment
- 2026-07-10 01:40 UTCGHSA enrichment
- 2026-07-09 21:18 UTCGHSA enrichment
- 2026-07-09 16:56 UTCGHSA enrichment
- 2026-07-09 12:33 UTCGHSA enrichment
- 2026-07-09 08:11 UTCGHSA enrichment
- 2026-07-09 03:49 UTCGHSA enrichment
- 2026-07-08 23:27 UTCGHSA enrichment
- 2026-07-08 19:05 UTCGHSA enrichment
- 2026-07-08 14:44 UTCGHSA enrichment
- 2026-07-08 10:22 UTCGHSA enrichment
- 2026-07-08 05:59 UTCGHSA enrichment
- 2026-07-08 01:37 UTCGHSA enrichment
- 2026-07-07 21:15 UTCGHSA enrichment
- 2026-07-07 19:01 UTCCISA KEV update
- 2026-07-07 17:16 UTCCISA KEV update
- 2026-07-07 16:53 UTCGHSA enrichment
- 2026-07-07 12:31 UTCGHSA enrichment
Publicly available exploits
(10 references)Working exploit code is in the public domain (10 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCxaitax/WinRAR-CVE-2023-38831First seen Sep 3, 2023
This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is executed, leading to code execution.
Open source ↗ - GitHub PoCMorDavid/CVE-2023-38831-Winrar-Exploit-Generator-POCFirst seen Aug 30, 2023
This is a POC for the CVE-2023-3883 exploit targeting WinRAR up to 6.22. Modified some existing internet-sourced POCs by introducing greater dynamism and incorporated additional try-except blocks within the code.
Open source ↗ - GitHub PoCHDCE-inc/CVE-2023-38831First seen Aug 28, 2023
CVE-2023-38831 PoC (Proof Of Concept)
Open source ↗ - GitHub PoCknight0x07/WinRAR-Code-Execution-Vulnerability-CVE-2023-38831First seen Aug 28, 2023
Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)
Open source ↗ - GitHub PoCMaalfer/CVE-2023-38831_ReverseShell_Winrar-RCEFirst seen Aug 28, 2023
Pasos necesarios para obtener una reverse shell explotando la vulnerabilidad de winrar CVE-2023-38831 en versiones anteriores a 6.23.
Open source ↗ - GitHub PoCahmed-fa7im/CVE-2023-38831-winrar-expoit-simple-PocFirst seen Aug 28, 2023
CVE-2023-38831 winrar exploit generator and get reverse shell
Open source ↗ - GitHub PoCGarck3h/cve-2023-38831First seen Aug 27, 2023
一款用于生成winrar程序RCE(即cve-2023-38831)的POC的工具。
Open source ↗ - GitHub PoCignis-sec/CVE-2023-38831-RaRCEFirst seen Aug 27, 2023
An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831, WinRAR RCE before versions 6.23
Open source ↗ - GitHub PoCb1tg/CVE-2023-38831-winrar-exploitFirst seen Aug 25, 2023
CVE-2023-38831 winrar exploit generator
Open source ↗ - GitHub PoCBoredHackerBlog/winrar_CVE-2023-38831_lazy_pocFirst seen Aug 24, 2023
lazy way to create CVE-2023-38831 winrar file for testing
Open source ↗
Frequently asked(6)
What is CVE-2023-38831?
When was CVE-2023-38831 disclosed?
Is CVE-2023-38831 actively exploited?
What is the CVSS score of CVE-2023-38831?
Which products are affected by CVE-2023-38831?
How do I remediate CVE-2023-38831?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2023-38831
Is Your Infrastructure Affected by CVE-2023-38831?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.