CVE-2025-60835
IZArc · IZArc
A path traversal vulnerability in the unrar.dll component of IZArc v4.6 allows attackers to write files to unauthorized locations on the host system.
Executive summary
A high-severity path traversal vulnerability in IZArc v4.6 permits attackers to perform arbitrary file writes, potentially leading to system compromise.
Vulnerability
The vulnerability exists in the unrar.dll component, which fails to properly sanitize file paths within RAR archives. An attacker can craft a malicious archive to perform path traversal, resulting in an arbitrary file write on the host system during the extraction process.
Business impact
With a CVSS score of 7.8, this flaw presents a significant security risk. Successful exploitation allows an attacker to overwrite critical system files or place malicious executables in startup directories, leading to unauthorized code execution and complete system takeover.
Remediation
Immediate Action: Users of IZArc v4.6 should monitor the official vendor advisory for the availability of a patched version or an updated unrar.dll component. If no patch is currently available, consider utilizing alternative archive software that is not affected by this vulnerability.
Proactive Monitoring: Review file integrity logs and monitor for unexpected file modifications or the creation of new files in sensitive system directories, especially following archive extraction operations.
Compensating Controls: Utilize host-based intrusion prevention systems to detect and block attempts to write files to protected system locations. Ensure that users operate with the least privilege necessary to minimize the impact of a potential write-based attack.
Exploitation status
Public Exploit Available: No (no confirmed public exploit available).
Analyst recommendation
The risk of arbitrary file write necessitates immediate attention. Organizations should audit their environments for the presence of IZArc v4.6 and discourage its use until a definitive fix is verified and deployed.