WinRAR SFX archives can run PowerShell without being detected

Discussion in 'other security issues & news' started by Malcontent, Apr 3, 2023.

  1. Malcontent

    Malcontent Registered Member

    Joined:
    Dec 30, 2005
    Posts:
    634
    Location:
    Cleveland, Ohio USA
    WinRAR SFX archives can run PowerShell without being detected
     
  2. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,147
    Location:
    USA
    I assume you would need to know the .exe was a SFX file, open it with WinRAR, but not execute it. Lots of maybes there. I also assume this is pretty easy to exploit.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.