CVE-2023-40477 is a remote code execution vulnerability in RARLAB WinRAR involving the processing of recovery volumes. The flaw stems from improper validation of user-supplied array index data while handling recovery-volume content, leading to a memory access past the end of an allocated buffer. This out-of-bounds memory operation can corrupt process memory and is exploitable in the context of archive parsing. Successful exploitation occurs when a target opens a specially crafted archive-related file or otherwise causes WinRAR to process attacker-controlled recovery-volume data, allowing arbitrary code execution in the context of the current WinRAR process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for CVE-2023-40477, a heap overflow vulnerability in WinRAR versions up to 6.22. The main exploit file is 'cve_2023_40477_poc.py', a Python script that generates a set of malformed RAR recovery volume files (.rev). The exploit process involves creating a RAR4 archive with recovery volumes, deleting the first recovery volume (.r01), and then using the script to generate malformed .rev files. When a vulnerable version of WinRAR attempts to extract the archive with these files, it will crash, demonstrating the vulnerability. The repository also includes a set of example RAR recovery volume files in the 'example_poc_after_gen' directory, which can be used directly for testing. The exploit is local in nature, requiring the user to interact with the crafted archive files. No network endpoints or remote attack vectors are present. The repository is structured with a README providing detailed instructions, the PoC script, and example files for demonstration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A 2023 WinRAR recovery-volume handling flaw referenced as a variant related to CVE-2026-14191.
The content only mentions this CVE as part of a recent searches list and provides no vulnerability details or significance.
A vulnerability in the UnRAR library that may affect ClamAV because it bundles UnRAR as libclamunrar; the issue prompted critical patch releases and an upgrade to UnRAR/libclamunrar version 6.2.10.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.