CVE-2005-4620
WinRAR 3.50 - Local Buffer Overflow via Long Command-Line Argument
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-4620. PoCs published by c0d3r, K4P0.
AI-analyzed exploit summary This exploit targets a local buffer overflow vulnerability in WinRAR 3.3.0 and below. It uses a crafted command-line argument to trigger the overflow and execute shellcode, resulting in a reverse shell on port 4444.
Description
Buffer overflow in WinRAR 3.50 and earlier allows local users to execute arbitrary code via a long command-line argument. NOTE: because this program executes with the privileges of the invoking user, and because remote programs do not normally have the ability to specify a command-line argument for this program, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.
Exploits (2)
This exploit targets a local buffer overflow vulnerability in WinRAR 3.3.0 and below. It uses a crafted command-line argument to trigger the overflow and execute shellcode, resulting in a reverse shell on port 4444.
This exploit targets a buffer overflow vulnerability in WinRAR 3.30 by crafting a malicious command-line argument. It uses a JMP ESP offset and shellcode to execute a command shell (cmd.exe).