WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng language file in the installation directory. Attackers can trigger the crash by opening an archive and pressing the test button, causing an access violation at memory address 004F1DB8 when the application attempts to read invalid data.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rarlab
Rarlab winrar |
|
| Vendors & Products |
Rarlab
Rarlab winrar |
Mon, 06 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 05 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng language file in the installation directory. Attackers can trigger the crash by opening an archive and pressing the test button, causing an access violation at memory address 004F1DB8 when the application attempts to read invalid data. | |
| Title | WinRAR 5.61 Denial of Service via Malformed Language File | |
| Weaknesses | CWE-379 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-05T20:45:28.606Z
Updated: 2026-04-06T18:07:45.413Z
Reserved: 2026-04-05T13:27:54.997Z
Link: CVE-2019-25677
Updated: 2026-04-06T18:07:40.374Z
Status : Awaiting Analysis
Published: 2026-04-05T21:16:45.800
Modified: 2026-04-07T13:20:35.010
Link: CVE-2019-25677
No data.