What is RARLAB UnRAR?
UnRAR is the official command-line tool for extracting RAR archives, developed by RARLAB. It is used across Linux and Unix systems to unpack RAR-format compressed files, including in email security gateways, file servers, and collaboration platforms. Zimbra Collaboration Suite uses UnRAR to extract and scan RAR email attachments for malicious content — which turned CVE-2022-30333 from a file-write primitive into a complete unauthenticated RCE on Zimbra mail servers.
Overview
CVE-2022-30333 is a path traversal vulnerability (CWE-22) in RARLAB's UnRAR tool for Linux and Unix. When extracting a specially crafted RAR archive, UnRAR writes files to paths outside the intended extraction directory — including arbitrary locations on the filesystem accessible to the process. When exploited against Zimbra Collaboration Suite (which runs UnRAR as part of email scanning), an unauthenticated attacker can send a malicious RAR email to a Zimbra server and achieve remote code execution by writing a JSP web shell into the Zimbra web root.
Affected Versions
| Product | Vulnerable | Fixed |
|---|---|---|
| UnRAR (Linux/Unix) | < 6.12 | 6.12 |
| Zimbra Collaboration Suite | Any using UnRAR < 6.12 | Update UnRAR; ZCS patches also released |
Windows UnRAR is not affected by this specific vulnerability.
Technical Details
The path traversal occurs because UnRAR on Linux/Unix does not properly sanitize archive entry filenames containing symlinks or path separators that point outside the target extraction directory. A crafted RAR archive can include a symlink entry followed by a file that follows the symlink, effectively writing to an arbitrary location.
- Exploitation via Zimbra: Zimbra processes incoming email attachments including RAR files using UnRAR for content inspection. An attacker sends a crafted RAR email to any address on the Zimbra server. Zimbra's Amavis content scanner extracts the RAR via UnRAR. The traversal writes a JSP file to the Zimbra webapps directory. The attacker then accesses the JSP via HTTP to execute commands — all without authentication.
- Authentication required: None — sending an email to any address on the server is sufficient
- User interaction required: None — Zimbra processes attachments automatically
- CVSS reflects only file write (Integrity: High; no Confidentiality or Availability impact from the traversal alone); actual RCE impact in the Zimbra context far exceeds the base score
Discovery
Discovered by Simon Scannell from SonarSource, who reported it to RARLAB and coordinated disclosure.
Exploitation Context
CISA added CVE-2022-30333 to KEV in August 2022, driven by observed exploitation against Zimbra servers. The combination of a path traversal in UnRAR + Zimbra's automatic email scanning created a zero-click RCE on a widely deployed enterprise mail platform. Zimbra is used by thousands of organizations including government agencies, and threat actors systematically targeted exposed Zimbra installations. Google TAG later attributed Zimbra-focused attacks to multiple nation-state actors in 2022.
Remediation
- Upgrade UnRAR to version 6.12 or later on all Linux/Unix systems
- Apply the Zimbra Collaboration Suite security patches that address this issue — Zimbra released updates bundling the fixed UnRAR
- If immediate patching is not possible, remove or disable UnRAR processing in Zimbra's Amavis configuration as a temporary workaround
- Review Zimbra web directories for unauthorized JSP files:
find /opt/zimbra/jetty/webapps -name "*.jsp" -newer /opt/zimbra/conf/zmconfigd.cf - Audit Zimbra logs for unusual HTTP requests to JSP files that do not correspond to the Zimbra application
Key Details
| Property | Value |
|---|---|
| CVE ID | CVE-2022-30333 |
| Vendor / Product | RARLAB — UnRAR |
| NVD Published | 2022-05-09 |
| NVD Last Modified | 2025-11-03 |
| CVSS 3.1 Score | 7.5 |
| CVSS 3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
| Severity | HIGH |
| CWE | CWE-22 find similar ↗ |
| CISA KEV Added | 2022-08-09 |
| CISA KEV Deadline | 2022-08-30 |
| Known Ransomware Use | ⚠️ Yes |
CVSS 3.1 Breakdown
Required Action
Timeline
| Date | Event |
|---|---|
| 2022-05-06 | Simon Scannell (SonarSource) reports the vulnerability to RARLAB |
| 2022-05-09 | CVE published; RARLAB releases UnRAR 6.12 with fix |
| 2022-08-09 | Added to CISA Known Exploited Vulnerabilities catalog |
| 2022-08-30 | CISA BOD 22-01 remediation deadline |
References
| Resource | Type |
|---|---|
| RARLAB — UnRAR 6.12 for Linux (patched release) | Vendor Advisory |
| SonarSource — Research on Zimbra Vulnerabilities | Security Research |
| NVD — CVE-2022-30333 | Vulnerability Database |
| CISA KEV Catalog Entry | US Government |