Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-38831 — CVE-2023-38831 - WinRAR | Kitploit
Tools/GitHubGitHub/mishra0230/cve-2023-38831
Vulnerability AnalysisExploitationWeb Application ExploitationForensicsMalware AnalysisPenetration TestingThreat IntelligencePapers & ResearchLearning & EducationIncident ResponseBinary Exploitation
528 months agoNot yet reviewed
GitHub
mishra0230/cve-2023-38831

CVE-2023-38831

CVE-2023-38831 - WinRAR

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Detection Logic for CVE-2023-38831 WinRAR Exploit

This repository contains a detection logic for CVE-2023-38831 (WinRAR ZIP file spoofing / double-extension exploit) with raw queries / code blocks and ETW-specific provider names + Event IDs. A vulnerable version of WinRAR (< 6.23) on the target system

Behavioral summary

CVE-2023-38831 is exploited when:

  • User opens a malicious ZIP in WinRAR

  • The archive contains:

    ● A decoy file (e.g., invoice.pdf )

    ● A directory with the same name (e.g., invoice.pdf )

    ● Inside the directory "two" files with the same name but slightly different names(for one file space and that ends any extension like if 1st file is a "invoice.pdf " then 2nd one may be any script or executable like "invoice.pdf .cmd")

  • WinRAR executes the script or executable instead of opening the document (“PDF” in this case)

  • This Execution is triggered via calling the function ShellExecuteExW to execute the file, passing in shExecInfo(ShellExecute via Explorer )

  • WinRAR spawns a child process (cmd, powershell, mshta, wscript, exe as same as whatever present inside the folder)

  • Execution often occurs from Temp / AppData / extracted path

Attack summary

Flow Summary User opens archive

  ↓
  
WinRAR shows decoy file

  ↓
  
User double-clicks document

  ↓
  
WinRAR extracts directory with same name
  ↓
  
Executable written to *.pdf\*.pdf .exe
  ↓
  
ShellExecute via Explorer
  ↓
  
ImageLoad of executable

  ↓
  
Payload execution

Why This Flow Matters for Detection

●	No macro usage

●	No process creation dependency

●	Exploit hinges on filesystem masquerading

●	High-confidence, low-noise signal

Important technical details

  • The files are written in a special structure

    Like have two objects (File/Dir) with the same name and when you have a file and a directory with the same name, in an archive file and want to open the file temporarily, by double-clicking on it(target file) in the opened archive file, the Winrar extracts this file for you, Also extracts all files that have the same name as the target file. All of them has wrote in a temporary directory in the %tmp% path.

      	| File/Dir name                                          | Extraction path                                                                   |
      	
      	| ------------------------------------------------------ | --------------------------------------------------------------------------------- |
      	
      	| CLASSIFIED_DOCUMENTS.txt <–target file clicked on it   | `C:\Users\UsersName\AppData\Loca\Temp\Rar$DIa8432.13968\CLASSIFIED_DOCUMENTS.txt\`|
      	
      	| CLASSIFIED_DOCUMENTS.txt .cmd <– the file in directory | `C:\Users\UsersName\AppData\Loca\Temp\Rar$DIa8432.13968\CLASSIFIED_DOCUMENTS.txt\`|
      	
    
  • If there are two files in a temporary (decompression) directory with the same name but different sizes (for example, 20k and 12k) and you open the archive and open the first file, 1.txt, which is 20k bytes in size, Winrar will prompt you to replace a file with the second file, 1.txt, which is 10K in size. If you click "Yes," only the second file, 1.txt, will open. This condition can be added for exclusion.

Important point for detection logic

  • Process execution triggered from a ZIP extraction path or temp directory, with a misleading extension or folder masquerading as a file

  • When WinRAR releases a file for decompression in the temporary directory, it must contain two files with the same name but slightly different names (space and that ends any extension ), like name as the main file a “ ” (CLASSIFIED_DOCUMENTS.pdf ) at the end of its name and then a “.cmd” (CLASSIFIED_DOCUMENTS.pdf .cmd).

  • When WinRar loads a DLL and calls the ShellExecuteExA function, the parameter "pExecInfo" has a path  with a space and that ends any extension, such as "CLASSIFIED_DOCUMENTS.pdf .cmd."

  • ETW Providers and Detection Philosophy (ETW-Only) ETW Providers

      	| Purpose                    | ETW Provider                          |
      	
      	| -------------------------- | ------------------------------------- |
      	
      	| Process creation           | `Microsoft-Windows-Kernel-Process`    |
      	
      	| Command line visibility    | `Microsoft-Windows-Security-Auditing` |
      	
      	| File operations (optional) | `Microsoft-Windows-Kernel-File`       |
      	
    
     Detection will rely on (If No ProcessStart, CreateProcess, or EDR-style parent/child logic):
     
      	●	File system ETW
      	
      	●	Shell / Explorer ETW
      	
      	●	Image load ETW (optional, non-create)
      	
      	●	Command line ETW (optional)
      	
      
     Core ETW Providers
     
      	| Purpose                    | ETW Provider                          |
      	
      	| -------------------------- | ------------------------------------- |
      	
      	| Directory creation         | `Microsoft-Windows-Kernel-File`       |
      	
      	| EXE creation               | `Microsoft-Windows-Kernel-File`       |
      	
      	| Shell execution            | `Microsoft.Windows.ShellExecute`      |
      	
      	| Image load                 | `Microsoft-Windows-Kernel-Image`      |
      	
      	| Explorer                   | `Microsoft-Windows-Explorer`          |
      	
      	| Shell                      | `Microsoft-Windows-Shell-Core`        |	
    

Raw detection logic

At a high level, the logic detects:

			●	WinRAR.exe initiating file writes

			●	Creation of both a directory and a file with the same basename

			●	Executable extension materializing after rename or overwrite

			●	Sequence occurring within a tight time window (<2s)

This pattern is extremely rare in benign workflows but core to the exploit’s execution path.

			●	The rule intentionally avoids:

			●	Command-line inspection

			●	Child process tracking

			●	Full file hashing

Core logic detection

Core logic detection is mentioned below, along with a confidence level and a brief justification.

Download Tool