CVE-2025-31334

Published Apr 3, 2025

Last updated a year ago

Overview

Description
Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary code may be executed.
Source
vultures@jpcert.or.jp
NVD status
Awaiting Analysis

Risk scores

CVSS 3.0

Type
Secondary
Base score
6.8
Impact score
5.9
Exploitability score
0.9
Vector string
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Severity
MEDIUM

Weaknesses

vultures@jpcert.or.jp
CWE-356

Social media

Hype score
Not currently trending
  1. #Vulnerability #CVE202531334 CVE-2025-31334: WinRAR Flaw Enables Mark-of-the-Web Bypass and Arbitrary Code Execution https://t.co/SL0zHiL196

    @Komodosec

    8 Jun 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Actively exploited CVE : CVE-2025-31334

    @transilienceai

    16 Apr 2025

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. 🚨 La vulnerabilidad CVE-2025-31334 en WinRAR permite a atacantes eludir la Marca de la Web (MotW) y ejecutar código arbitrario. Los emails maliciosos con adjuntos .rar son especialmente peligrosos, ya que pueden comprometer tu sistema. https://t.co/cZX8k6HsaJ

    @AlfonsoBalcells

    15 Apr 2025

    57 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    1 Reply

    1 Quote

  4. Actively exploited CVE : CVE-2025-31334

    @transilienceai

    12 Apr 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. 2. WinRAR Güvenlik Açığı (CVE-2025-31334) WinRAR’da tespit edilen bu açık, sembolik bağlantılar kullanılarak Windows’un internetten indirilen dosyalara uyguladığı güvenlik etiketlerinin (MotW) atlatılmasına olanak tanıyor. Bu durum, kullanıcıların zararlı dosyaları farkında

    @MuratDemirtas

    12 Apr 2025

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🛡️ ¿Usas WinRAR? Cuidado con esta falla crítica que podría infectar tus dispositivos. Una nueva vulnerabilidad permite burlar la alerta de seguridad de Windows, conocida como Mark of the Web (MotW). 📎 Es la falla CVE-2025-31334. Afecta todas las versiones de WinRAR anteriore

    @CycuraMX

    11 Apr 2025

    654 Impressions

    9 Retweets

    23 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  7. Vuln en WinRAR 2025 Una vulnerabilidad 🤏🏼 identificada como CVE-2025-31334 afecta a WinRAR y permite a los atacantes eludir las advertencias de seguridad de Windows y ejecutar código malicioso sin generar alarmas. https://t.co/VNNb3bnzSE #autonomihacker #ciberseguridad #winrar

    @R4ptor01

    11 Apr 2025

    25 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. لطفا Winrar را update کنید. به تازگی برای برنامه پرکاربرد winrar آسیب پذیری با کد شناسایی CVE-2025-31334 و از نوع RCE منتشر شده است. نسخه های قبل از 7.11 مربوط به این برنامه دارای این آسیب پذیری هستند. https://t.co/Poz3aKY03t https://t.co/cfCXEgrhDW

    @AmirHossein_sec

    11 Apr 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. #CybersecurityNEWS🔴👨💻👾 Una nueva vulnerabilidad identificada como CVE-2025-31334 ha puesto en riesgo a los usuarios de WinRAR, permitiendo a los atacantes evadir el mecanismo de seguridad Mark of the Web (MotW) Ver más: https://t.co/y9sOZmzdaU #ciberseguridad #DevelNews htt

    @develsecurity

    11 Apr 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. A vulnerability in WinRAR file archiver solution could be exploited to bypass the Mark of the Web (MotW) security warning and execute arbitrary code on a Windows machine. CVE-2025-31334 affects all WinRAR versions except the most recent release 7.11. https://t.co/xeDmHRXNYw https

    @riskigy

    7 Apr 2025

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Falha no WinRAR: A vulnerabilidade CVE-2025-31334, presente em versões anteriores à 7.11 do WinRAR, possibilita o bypass da segurança Mark of the Web do Windows, permitindo executar códigos maliciosos sem alertas de segurança. https://t.co/3orB2zC9mI

    @caveiratech

    7 Apr 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Ojo! actualicen #WinRAR La vulnerabilidad CVE-2025-31334 puede ayudar a un atacante a eludir la advertencia de seguridad de MotW en #Windows al abrir un enlace simbólico que apunta a un archivo ejecutable en cualquier versión de WinRAR anterior a la 7.11. https://t.co/wAPd28SsC

    @SoyITPro

    7 Apr 2025

    1486 Impressions

    15 Retweets

    43 Likes

    5 Bookmarks

    2 Replies

    1 Quote

  13. พบช่องโหว่ร้ายแรงใน WinRAR เสี่ยงให้แฮกเกอร์รันโค้ดแฝงที่เป็นอันตราย https://t.co/e702ZpOAoX CVE-2025-31334

    @ohmohm

    7 Apr 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. New WinRAR flaw (CVE-2025-31334) lets attackers bypass Windows security alerts using crafted symlinks—no MotW warning! Fixed in v7.11. Update NOW & avoid sketchy archives. https://t.co/pThMc7Z23V #CyberSecurity #WinRAR #UpdateNow https://t.co/J32tqGbeAa

    @dCypherIO

    7 Apr 2025

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. WinRAR MotW bypass flaw fixed, update ASAP (CVE-2025-31334) https://t.co/8Ra9frn7EL https://t.co/iHPzHYd3a3

    @secharvesterx

    7 Apr 2025

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. EncryptHub e CVE-2025-31334: AI, frodi cyber con ChatGPT e falle WinRAR Sicurezza Informatica, BOT, bypass MotW, chatgpt, CVE-2025-31334, EncryptHub, malware, Mark of the Web Windows, opsec, Telegram, vulnerabilità, winrar https://t.co/cwsxHnxC46 https://t.co/l3kfOPZRrU

    @matricedigitale

    7 Apr 2025

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. WinRARの脆弱性(CVE-2025-31334)により、WindowsのMotWセキュリティ警告を回避し、任意コード実行が可能に。特定のシンボリックリンクを用いることで、攻撃者は警告なしにコードを実行できる。この問題はバージョン7.11で修正済み。 https://t.co/jb289gwZUu

    @01ra66it

    6 Apr 2025

    410 Impressions

    0 Retweets

    6 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  18. اكتشف كيف تتجاوز ثغرة WinRAR تنبيهات أمان Windows Mark of the Web (CVE-2025-31334) وكيف تحمي نفسك منها. تعرف على التفاصيل الآن! للمزيد ابحث في Google عن موقعي [سايبرو بلس سكيورتي] #WinRAR https://t.co/R5IYbOu4C0

    @CyberOPlus

    5 Apr 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 🚨 ¡Alerta de seguridad! Se ha detectado la vulnerabilidad WinRAR CVE-2025-31334. Descubre los riesgos, detalles y cómo protegerte en nuestro análisis completo 👉 https://t.co/aj5ZNJOfu5 #Seguridad #Cybersecurity #WinRAR

    @Tecnohack_ES

    4 Apr 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. اكتشاف ثغرة جديدة على WinRar CVE-2025-31334 الثغره موجودة من اصدار 7.11 وقبل الثغره تسمح للمهاجم بتشغيل اوامر خبيثه على مستعمل البرنامج كل الي عليك تحدث البرنامج لاخر نسخه 👍🏽 https://t.co/zwdaTLOEaK

    @HereHuss

    4 Apr 2025

    69 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  21. WinRAR MotW Vulnerability CVE-2025-31334 Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is ht

    @CareWeDoNot

    4 Apr 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. La vulnerabilidad de WinRAR permite la elusión de la marca de la Web y la ejecución de código arbitrario CVE-2025-31334 https://t.co/UtvJ63pEZo https://t.co/IvW4emINMO

    @elhackernet

    4 Apr 2025

    5559 Impressions

    46 Retweets

    111 Likes

    22 Bookmarks

    1 Reply

    1 Quote

  23. CVE-2025-31334: ข้อบกพร่องของ WinRAR ช่วยให้ Mark-of-the-Web Bypass และการประมวลผลรหัสโดยพลการ https://t.co/dbBJsZGSEM

    @freedomhack101

    4 Apr 2025

    14 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  24. CVE-2025-31334 Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions… https://t.co/BB91ICBZAM

    @CVEnew

    3 Apr 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. Critical WinRAR flaw (CVE-2025-31334) bypasses Mark-of-the-Web protections, enabling arbitrary code execution via malicious archives. Patch immediately: https://t.co/eYj4qiZJoi #CyberSecurity #Vulnerability

    @adriananglin

    3 Apr 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. CVE-2025-31334: WinRAR Flaw Enables Mark-of-the-Web Bypass and Arbitrary Code Execution https://t.co/Nmu2a7ERrG

    @Dinosn

    3 Apr 2025

    9742 Impressions

    64 Retweets

    156 Likes

    43 Bookmarks

    2 Replies

    1 Quote

  27. CVE-2025-31334: WinRAR Flaw Enables Mark-of-the-Web Bypass and Arbitrary Code Execution Learn about CVE-2025-31334, a new vulnerability in #WinRAR that can bypass Windows security and execute malicious code. https://t.co/bQjOjXeKXX

    @the_yellow_fall

    3 Apr 2025

    30 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. CVE-2025-31334 WinRAR Symbolic Link Security Bypass Enabling Arbitrary Code Execution Prior to 7.11 https://t.co/oMrDCe5Oyr

    @VulmonFeeds

    3 Apr 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.