CISA Warns Of Windows And UnRAR Bugs Exploited In The Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of two vulnerabilities exploited in the wild. The flaws have been added to the list of Known Exploited Vulnerabilities based on evidence of active exploitation.

For both vulnerabilities, federal authorities in the U.S. are expected to apply the updates from the vendors by August 30.

The first bug tracked as CVE-2022-34713 is formally referred to as DogWalk, while the second bug tracked as CVE-2022-30333 is a path traversal bug in the UnRAR utility for Linux and Unix systems.

The DogWalk vulnerability (CVE-2022-34713) is a vulnerability in MSDT that allows attackers to place a malicious executable program in the Windows Startup folder. According to Microsoft, successful exploitation requires user interaction that can be bypassed via social engineering, especially in email and web-based attacks.

The UnRAR bug (CVE-2022-30333) found in the UnRAR utility for Linux and Unix systems allows an attacker to use it to place a malicious file on the target system by extracting it to any location during the unpack operation.

For most affected versions of Windows, an unofficial patch for CVE-2022-34713 is available from the opatch micropatching service. Microsoft has also fixed the bug as part of the security updates for Windows released in August 2022.

The sources for this piece include an article in BleepingComputer.

Top Stories

Related Articles

May 31, 2025 A coordinated supply chain attack has compromised between 500 and 1,000 e-commerce websites by exploiting vulnerabilities in 21 more...

May 31, 2025 A widely used open-source Go library, easyjson, used in healthcare, finance and even defence has come under scrutiny more...

May 31, 2025 (EDITORIAL) A messaging tool used by Trump administration officials to archive encrypted Signal messages has been hacked — more...

April 22, 2025 Anthropic, a leading artificial intelligence company, anticipates that AI-powered virtual employees could begin operating within corporate networks as more...

Jim Love

Jim Is and author and pud cast host with over 40 years in technology.