CVE-2019-25677
WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng language file in the installation directory. Attackers can trigger the crash by opening an archive and pressing the test button, causing an access violation at memory address 004F1DB8 when the application attempts to read invalid data.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.43%
- CWE
- CWE-379
- Published
- 2026-04-05
- Last modified
- 2026-07-15
Affected products
- Win-Rar WinRAR
Weakness type
Related vulnerabilities
- CVE-2026-69482 — Windows Error Reporting Tampering Vulnerability
- CVE-2026-85028 — Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit
- CVE-2026-82346 — HP ImageDiags - Potential Escalation of Privilege
- CVE-2026-63693 — Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following')...
- CVE-2026-12555 — HP Easy Start for macOS - Security Update
- CVE-2026-50544 — NortheBridge/luminalshine has Incorrect Permission Assignment for Critical Resource and Creation of Temporary File in Directory with Insecure Permissions
- CVE-2026-14551 — Local Privilege Escalation in servereye client (sensorhub)
- CVE-2026-46388 — osquery: Unprivileged users can temporarily read file carve contents