CVE-2024-36052
HIGHWinRAR < 7.00 - Screen Output Spoofing via ANSI Escape Sequences
Title source: llmDescription
RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://sdushantha.medium.com/ansi-escape-injection-vulnerability-in-winrar-a2cbfac4b983
Release Notes
https://www.rarlab.com/rarnew.htm
Scores
CVSS v3
7.5
EPSS
0.0075
EPSS Percentile
51.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-150
Status
published
Products (1)
rarlab/winrar
< 7.00
Published
May 21, 2024
Tracked Since
Feb 18, 2026