August 9, 2022 · Applied Cybernetics Group
CVE-2022-30333 — RARLAB UnRAR
known ransomware use
RARLAB UnRAR Directory Traversal Vulnerability
- Added to KEV
2022-08-09- Federal due date
2022-08-30- Vendor
- RARLAB
- Product
- UnRAR
- EPSS
- 99.9th percentile (score 0.991, as of
2026-09-16) - NVD CVSS v3.1
- 7.5 (HIGH)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2022-30333
CISA short description
RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
Required action
Apply updates per vendor instructions.
NVD description
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.