High severity vuln in WinRAR could allow code to run when files are opened

Discussion in 'other security issues & news' started by stapp, Aug 21, 2023.

  1. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    27,171
    Location:
    UK
  2. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,943
    Location:
    Outer space
    Thanks for the notice!
     
  3. nicolaasjan

    nicolaasjan Registered Member

    Joined:
    Sep 23, 2018
    Posts:
    985
    Location:
    The Netherlands
  4. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    27,171
    Location:
    UK
    Some folk just seem to stick on old versions :(
     
  5. pegas

    pegas Registered Member

    Joined:
    May 22, 2008
    Posts:
    2,972
  6. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,147
    Location:
    USA
    True, a lot of them don't pay any attention to such things. That said, it's a full time job keeping your PC updated. Nobody else where I work has a clue. :eek:
     
  7. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    6,294
    the patch concerns rar4 recovery volumes. rar5 is now 10 year default setting.
    the patch landed in winrar(.exe), or grab unrar lib like TC made it.
    and yes, older versions of winrar(.exe) are vulnerable.
     
  8. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Guys, I don't know if this has been posted before, but this flaw was actually used by hackers. However, wouldn't a firewall (default-deny) easily block such an attack?

    https://www.bleepingcomputer.com/ne...xploited-since-april-to-hack-trading-accounts
     
  9. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    6,294
    No. Why? and the cve is non-readable for reason.
     
  10. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    What I'm saying is that I'm actually surprised this flaw has been already actively exploited. But yes, I believe a firewall will block this, since it needs to download malware in the background.
     
  11. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,147
    Location:
    USA
    That article gave me the impression that the malware was part of the archive.
     
  12. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    My bad, I somehow assumed it used some type of script to download malware, many attacks work like this. But in this particular case it wouldn't make sense since the user already downloaded the file.

    But what is clear is that they use all kinds of tricks to probably bypass the AV, strange that they don't mention if Win Defender could block it or not. Which is why I always recommend to install extra protection tools like anti-loggers to complement the AV.
     
  13. Malcontent

    Malcontent Registered Member

    Joined:
    Dec 30, 2005
    Posts:
    634
    Location:
    Cleveland, Ohio USA
    PSA: it’s time to update WinRAR due to a big security vulnerability
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.