Critical flaw puts 500 million WinRAR users at risk of being pwned by unzipping a file
500 million, yes half a billion, WinRAR users are at risk of being pwned thanks to a critical flaw that could allow hackers to take control of victims’ computers. Vulnerability Lab, via the Full Disclosure mailing list, put the world on notice about a remote code execution vulnerability in the latest version of WinRAR, WinRAR 5.21. If the critical bug in WinRAR is exploited by an attacker, then a victim’s system could be compromised by simply opening the file.
Whether it’s movies, music, applications, photos, pictures, gaming mods, or something else, if it’s a digital file then you can likely zip or unzip it. You may have used the popular WinRAR tool to pack or unpack a RAR, ZIP, 7Z, TAR, EXE, ISO, CAB or another supported archive. Let’s say, for example, that you have a torrent file. In this case, if you used the latest version of WinRAR to decompress an archive that contained malicious code, it would execute immediately upon unzipping the infected file. This could lead to not only your computer being compromised, but potentially also your network.
To read this article in full or to leave a comment, please click here
