The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse file with a name similar to an extensionless filename that was selected by the user.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/79666 | vdb entry |
http://jvn.jp/en/jp/JVN64636058/index.html | third party advisory vendor advisory |
http://www.securitytracker.com/id/1034881 | vdb entry |
http://jvndb.jvn.jp/jvndb/JVNDB-2015-000199 | third party advisory vendor advisory |