Nasty code-execution bug in WinRAR threatened millions of users for 14 years

Discussion in 'other security issues & news' started by ronjor, Feb 20, 2019.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,883
    Location:
    Texas
  2. guest

    guest Guest

    Nasty WinRAR bug is being actively exploited to install hard-to-detect malware
    March 15, 2019
    https://arstechnica.com/information...-exploited-to-install-hard-to-detect-malware/
     
  3. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,883
    Location:
    Texas
  4. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,642
    Location:
    USA
    If you open an unsolicited email attachment in ace or rar format, you are pretty much asking for trouble. If you thought it was a good idea, someone is probably going to get you anyway though so have fun. We'll probably see you here, asking for help. :D
     
  5. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Also, the mitigation for this if you can't upgrade to the latest ver. of WinRAR or don't want to apply the third party patch is to remove he unacev2.dll from the WinRAR directory. Or, alternatively disassociate the .ace extension.
     
  6. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    I though WinRAR had a feature where a user can tie-in so to speak an AV to scan the unpacked archives. It did when I used it.
    In fact an older version still in one of my folders offers that option. That is if users actually set that feature or not is another matter.
     
  7. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,883
    Location:
    Texas
    Analysis of a targeted attack exploiting the WinRar CVE-2018-20250 vulnerability
     
  8. noway

    noway Registered Member

    Joined:
    Apr 24, 2005
    Posts:
    461
    Thanks OP for letting us know.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.