CVE-2024-55504
MEDIUMRAR Extractor - Unarchiver Free and Pro <6.4.0 - Code Injection
Title source: llmDescription
An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote control and unauthorized access to sensitive user data via the exploit_combined.dylib component on MacOS.
Exploits (1)
Scores
CVSS v3
5.5
EPSS
0.0239
EPSS Percentile
85.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-94
Status
published
Published
Jan 21, 2025
Tracked Since
Feb 18, 2026