Back

CVE-2005-3262

Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when WinRAR displays diagnostic errors related to an invalid filename.

Published: Oct 20, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (11)

Vendor Product Version
rarlab winrar 2.90
rarlab winrar 3.0.0
rarlab winrar 3.10
rarlab winrar 3.10_beta3
rarlab winrar 3.10_beta5
rarlab winrar 3.11
rarlab winrar 3.20
rarlab winrar 3.40
rarlab winrar 3.41
rarlab winrar 3.42
rarlab winrar 3.50

GitHub Security Advisory GHSA-mqg5-xjp9-584v

Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 8.80%

Top 5% most likely to be exploited

Threat Score 32.6 / 100

Data Sources

NVD EPSS GitHub