A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to inconsistencies between the Central Directory and Local File Header entries in ZIP files. When viewed in WinRAR, the file name from the Central Directory is displayed to the user, while the file from the Local File Header is extracted and executed. An attacker can leverage this flaw to spoof filenames and trick users into executing malicious payloads under the guise of harmless files, potentially leading to remote code execution.
History

Sat, 26 Jul 2025 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Rarlab
Rarlab winrar
Vendors & Products Rarlab
Rarlab winrar

Fri, 25 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 25 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
Description A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to inconsistencies between the Central Directory and Local File Header entries in ZIP files. When viewed in WinRAR, the file name from the Central Directory is displayed to the user, while the file from the Local File Header is extracted and executed. An attacker can leverage this flaw to spoof filenames and trick users into executing malicious payloads under the guise of harmless files, potentially leading to remote code execution.
Title WinRAR < 5.00 Filename Spoofing RCE
Weaknesses CWE-20
CWE-434
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-07-25T15:59:39.205Z

Updated: 2025-07-25T17:40:59.878Z

Reserved: 2025-07-24T20:58:56.840Z

Link: CVE-2014-125119

cve-icon Vulnrichment

Updated: 2025-07-25T17:40:53.040Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-25T16:15:26.507

Modified: 2025-07-29T14:14:55.157

Link: CVE-2014-125119

cve-icon Redhat

No data.