Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
winrar_CVE-2023-38831_lazy_poc — lazy way to create CVE-2023-38831 winrar file for testing | Kitploit
Tools/GitHubGitHub/boredhackerblog/winrar_cve-2023-38831_lazy_poc
Payload GenerationVulnerability AnalysisExploitationLearning & EducationLabs & Practice
GitHubboredhackerblog/winrar_cve-2023-38831_lazy_poc

winrar_CVE-2023-38831_lazy_poc

lazy way to create CVE-2023-38831 winrar file for testing

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
911693 years agoReviewed by Kitploit
Share

winrar_CVE-2023-38831_lazy_poc

lazy way to create CVE-2023-38831 winrar file for testing

Article that mentioned this vuln and the sample: https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/

version of winrar i was using is winrar 5.91.0

I took a malicious winrar file (049af32f678da5e344315ce46787e8fc https://gist.github.com/BoredHackerBlog/83cd5ca743189bf72b28ebaabe3c3df0) and removed all the included files besides the folder and main readme file

I created a new file with my command and added it to the ReadMe.txt folder and renamed the file to 'ReadMe.txt .cmd.'

image image image

'ReadMe.txt .cmd' works too, so does .bat, feel free to experiment

test.rar in this repo can be used for testing. It does not have the command file included. You'll have to add that on your own.

fyi: ideally, you don't want to use modified malicious files for testing. play with this in a sandbox or a VM...

Download Tool