Netskope Threat Labs

FILE-OTHER UnRAR directory traversal attempt

IPS-CFWIPS-SWG

2 SIDs: 60457, 64443

First seen
January 2025
Last seen
October 2026

Detects an archive exploiting CVE-2022-30333, a directory traversal in the UnRAR extraction library that writes files outside the destination directory. The crafted paths plant files into sensitive locations during a normal extraction action.