Bug in Popular WinRAR Software can be used to achieve remote code execution (RCE)

Discussion in 'other security issues & news' started by guest, Oct 21, 2021.

  1. guest

    guest Guest

    Bug in Popular WinRAR Software Could Let Attackers Hack Your Computer
    October 21, 2021
    https://thehackernews.com/2021/10/bug-in-free-winrar-software-could-let.html
    WinRAR’s vulnerable trialware: when free software isn’t free
     
  2. Floyd 57

    Floyd 57 Registered Member

    Joined:
    Mar 17, 2017
    Posts:
    1,296
    Location:
    Europe
    Winrar getting exposed music for my ears
     
  3. NormanF

    NormanF Registered Member

    Joined:
    Feb 20, 2009
    Posts:
    2,881
    Windows has a built in zip utility. People need a third party utility to extract rar. and other archives Windows can't open. I have Zip Extractor installed to take care of such extensions.
     
  4. Floyd 57

    Floyd 57 Registered Member

    Joined:
    Mar 17, 2017
    Posts:
    1,296
    Location:
    Europe
    Windows should include 7zip by default not that crap utility
     
  5. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    7 Zip does those duties on this end. Before then WinZip for many moons and seasons.
     
  6. NormanF

    NormanF Registered Member

    Joined:
    Feb 20, 2009
    Posts:
    2,881
    They have an unofficial UWP for it in the Microsoft Store.
     
  7. Floyd 57

    Floyd 57 Registered Member

    Joined:
    Mar 17, 2017
    Posts:
    1,296
    Location:
    Europe
    UWPs :argh::argh::argh::argh::argh::argh::argh::argh::argh::argh::argh::argh::argh:
     
  8. Floyd 57

    Floyd 57 Registered Member

    Joined:
    Mar 17, 2017
    Posts:
    1,296
    Location:
    Europe
    yeah honestly just remove the built in utility and then when the user clicks Extract (dont remove the context menu) redirect him to 7zip site. then when the user installs 7zip it will remove the default windows context menu which only redirects to 7zip. not that hard to do.
     
  9. Seer

    Seer Registered Member

    Joined:
    Feb 12, 2007
    Posts:
    2,068
    Location:
    Serbia
    This issue has been fixed with version 6.02.

    https://www.win-rar.com/whatsnew.html?&L=0

     
  10. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    I personally not used WinRAR in a very long time (Windows XP) but it was ok.

    Oh in Windows 10 that default zip utility I suppose is alright to a point but 7Zip offers infinite options which makes it ideal for working with archives of many different types.
     
  11. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,076
    Location:
    UK
  12. davews

    davews Registered Member

    Joined:
    Apr 8, 2014
    Posts:
    21
    6.02 already supports Windows 11 cascaded menus....... it is not clear though what else is new.
     
  13. Hadron

    Hadron Registered Member

    Joined:
    Apr 1, 2014
    Posts:
    2,139
    What bug?
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.