我希望你先看这个链接 [https://github.com/b1tg/CVE-2023-38831-winrar-exploit]
我没有编写完整的漏洞利用程序。他编写了漏洞利用程序。 [https://github.com/b1tg]
他所做的只是修改了一些简单的东西,以通过 script.bat 文件获得一个反向 Shell
python cve-2023-38831-exp-gen.py <文件名 pdf,png,jpg> <script.bat> <输出文件名>
别忘了修改 ip 和端口的值
使用任何 pdf、png 或 jpg 文件
别忘了修改 script.bat 中的文件名
https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/
https://thehackernews.com/2023/08/winrar-security-flaw-exploited-in-zero.html