CVE-2022-30333 is a directory traversal vulnerability in RARLAB UnRAR versions prior to 6.12 on Linux and UNIX systems, allowing an attacker to write arbitrary files during an extract operation, notably to create a ~/.ssh/authorized_keys file for remote access. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and requires no user interaction, potentially leading to significant impact on system integrity. It is actively exploited in the wild, including in known ransomware campaigns, with public exploit modules available for Metasploit and significant community discussion and media coverage highlighting its exploitation, particularly against Zimbra servers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.12CPE matchmatch criteria | cpe:2.3:a:rarlab:unrar:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.