CVE-2025-31334
Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 1.24%
- CWE
- CWE-356
- Published
- 2025-04-03
- Last modified
- 2026-03-12
Affected products
- RARLAB WinRAR
Weakness type
Related vulnerabilities
- CVE-2026-0777 — Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2026-25805 — Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.
- CVE-2025-3839 — Epiphany: insecure external protocol invocation in epiphany
- CVE-2025-14414 — Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14415 — Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14412 — Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14418 — pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerability
- CVE-2025-14417 — pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability