Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-38831 — A POC demo on CVE-2023-38831 | Kitploit
Tools/GitHubGitHub/firfirdaus/cve-2023-38831
Payload GenerationVulnerability AnalysisExploitationPenetration TestingCommand and ControlLearning & Education
GitHubfirfirdaus/cve-2023-38831

CVE-2023-38831

A POC demo on CVE-2023-38831

View Repository
12 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-38831

A POC demo on CVE-2023-38831

Brief description of vulnerability

  • CVE-2023-38831 is a software vulnerability.
  • The software that was exploited is WinRAR, which is used widely by almost everyone.
  • It is a software that helps different documents or files to make it into small archives (zip file format) which helps to save space that makes file sharing easier and faster process.
  • This vulnerability was discovered in April 2023.
  • It affects Windows Operating system and version 6.22 and below.
  • It was caused by a faulty function in WinRAR backend codes called “winrar.7FF6CE909948” that does not check on the parameters and compare the names of files in the zip directory and allowing 2 identical file such as “document.pdf” and a bat script naming “document.cmd” to bypass and be extracted.
  • It requires user interaction for exploitation to be successful.

How does the vulnerability work?

image

Demonstration of the exploit

First part of the exploitation

The first half will take place at the attacker machine for the exploitation to begin.

image

1) Firstly, we will need to create the exploitation folder containing the malicious attachment, “pdf”, the exploitation python code and bat script by the following command: “git clone https://github.com/HDCE-inc/CVE-2023-38831”

 

image

2) This is what the folder contains before any exploitation take place,

  1. a document.pdf which is to lure the victim into clicking the malicious file
  2. an exploit.py for the exploitation code
  3. script.bat for run malicious script on victim machine

 

Picture2

3) Finding out kali machine IP address via ifconfig:

 

image

4) We will then modify the existing script on script bat to the following command line(above image)

“start” is for the command line process to begin, “/min” is to minimise the command prompt at the background, ncat is to start connecting to the attacker ip address and via port 4444, and lastly -e cmd.exe is to execute the command line on command prompt.

 

image

5) This shows the following exploit.py code being explained:

1 refers to the user input on the bait file name which is document.pdf, script file name which is bat.script and the output on what the victim see the RAR file as and in this case we will save it as getrich.rar.

2 refers to the checks done to validate if existing files exist in the CVE-2023-38831 folder in kali linux machine with the right naming convection and if the naming is wrong or duplicate file, error message will be printed and the program will stop and exit.

3 refers to creating a temporary file destination using os.mkdir() to stored the newly created file before being compressed into archive and used as workspace.

4 refers to a copy line, shutil.copyfile, to copy both the bait and script file to be stored in their respective directories within “tmp” to ensure that all the necessary files are correct and in placed before proceeding to next step. The next step, shutil.make_archieve, create an archive from the “tmp” called “tmp.zip” which contains everything in the “tmp” folder.

5 refers to the success of running the above code and successfully created a RAR file as the exploit via user input of the bait file, script file and output file name.

 

image

6) After getting our IP address and modifying the bat script, we can now proceed to create the malicious “.rar” by running the command “python exploit.py”

The exploit.py will require the user input on 3 fields, the bait file name that exists which is document.pdf, the script file name that we have modified previously which is script.bat and an output RAR file name to lure the victim into downloading and clicking on the file which requires a name that is suitable for and in this case we used “steps-to-generate-income.rar”. CVE-2023-38831 is then ready to exploit the victim machine.

 


Second part of the exploitation

The second half will then take place both on the kali machine and the victim machine which is a windows 11 VM.

image

1) We will first either create a malicious website or send the attachment across to the victim.
On the left side, we will execute “python -m http.server 8080”. This command is a process to capture which IP address access this malicious URL which we then can know the victim IP address and listens for different HTTP requests such as “200” by a specific IP address. On the right side, the victim is lured to this IP address and is baited to download the file “steps-to-generate-income.rar”.

 

image

2) Once the victim has successfully been lured to download the malicious file “steps-to-generate-income.rar”, it will show which IP address has downloaded the file together with the time frame. From this info, we can obtain the victim IP address.

 

image

3) We will then set up a ncat on port 4444 on the kali machine as port 4444 is to synchronise with the same port as the one written in the script.bat to be executed on the victim machine.
Once the victim clicks on the document.pdf, the bat.script will run the command line and minimise in the background in a instance and this allow a backdoor connection for the attacker.

 

Download Tool