# CVE-2025-31334

## Summary

- **CVE ID:** CVE-2025-31334
- **Severity:** MEDIUM
- **CVSS Score:** 6.8 (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H)
- **CWE:** CWE-356
- **Published:** Apr 3, 2025
- **Last Modified:** Mar 12, 2026

## Description

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed.

## Affected Products

- RARLAB — WinRAR (prior to 7.11)

## References

- [CNA](https://www.win-rar.com/start.html?&L=0)
- [CNA](https://jvn.jp/en/jp/JVN59547048/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.24%
- **EPSS Percentile:** 67.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._