CVE-2022-30333

HIGH KEV RANSOMWARE

UnRAR Path Traversal (CVE-2022-30333)

Title source: metasploit

Description

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

Exploits (7)

nomisec WORKING POC 14 stars
by rbowes-r7 · remote
https://github.com/rbowes-r7/unrar-cve-2022-30333-poc
nomisec WORKING POC 13 stars
by TheL1ghtVn · poc
https://github.com/TheL1ghtVn/CVE-2022-30333-PoC
nomisec WORKING POC 7 stars
by aslitsecurity · poc
https://github.com/aslitsecurity/Zimbra-CVE-2022-30333
nomisec WORKING POC
by paradox0909 · client-side
https://github.com/paradox0909/cve-2022-30333_online_rar_extracor
nomisec WORKING POC
by RakhithJK · poc
https://github.com/RakhithJK/CVE-2022-30333
metasploit WORKING POC EXCELLENT
by Simon Scannell, Ron Bowes · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/zimbra_unrar_cve_2022_30333.rb
metasploit WORKING POC EXCELLENT
by Simon Scannell, Ron Bowes · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/fileformat/unrar_cve_2022_30333.rb

Scores

CVSS v3 7.5
EPSS 0.9281
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CISA KEV 2022-08-09
VulnCheck KEV 2022-08-09
InTheWild.io 2022-08-09
ENISA EUVD EUVD-2022-52276
Ransomware Use Confirmed
CWE
CWE-22 CWE-59
Status published
Products (2)
debian/debian_linux 10.0
rarlab/unrar < 6.12
Published May 09, 2022
KEV Added Aug 09, 2022
Tracked Since Feb 18, 2026