Category: IT|Oct 20, 2023 | Author: Admin

WinRAR has a major security bug, and you have to install its fix manually

Share on

Attackers can utilize a bug to execute code on your PC when you open zipped files.

What you need to know


WinRAR has a serious security issue that's been utilized by attackers, including government-backed actors.


Fixes for the issue are already available, but many systems may still be vulnerable due to the fact that WinRAR must be updated manually.


If the vulnerability is utilized, attackers can execute arbitrary code when a user opens certain files, which can used for a variety of attacks.


 
WinRAR has a serious security vulnerability that has been used by attackers, including government-backed hacking groups. The issue was discovered by Google's Threat Analysis Group (TAG), which discussed the problem in depth in a blog post.

 

If the vulnerability is utilized, threat actors can attack systems in a variety of ways. The issue allows an attacker to execute arbitrary code when someone opens a zipped file.

 

Security patches for the vulnerability are already available, but some users and organizations may not have installed them that. That is, in part, due to the fact that WinRAR does not update automatically. That means anyone using the piece of software needs to seek out the update manually.

 

"Cybercrime groups began exploiting the vulnerability in early 2023 when the bug was still unknown to defenders. A patch is now available, but many users still seem to be vulnerable," said Google's TAG.

 

"TAG has observed government-backed actors from a number of countries exploiting the WinRAR vulnerability as part of their operations."

 

WinRAR version 6.24 and the older version 6.23 have fixes for the vulnerability. You can find those updates on the RARLAB website.

 

What is WinRAR?


WinRAR is a piece of software used to archive, encrypt, and compress folders into a single file. The .rar file format is a common alternative to the .zip format, thanks to the better encryption and compression algorithms used by .rar.

 

While WinRAR is a useful piece of software used by over half a billion people, it is perhaps more famous as a meme or as the butt of jokes. WinRAR famously has a "trial" period that's easy to circumvent, allowing users to access WinRAR for free forever. Jokes about purchasing WinRAR are common in tech circles.

 

When Microsoft announced native support for the .rar file format, WinRAR shared a meme on Twitter (now called X).

 

Native .rar support has since rolled out to Windows through the Windows 11 October 2023 Update. While the operating system supports .rar natively, some may still prefer to use WinRAR.

Sponsored Ads:

Comments:


Apple pauses iPadOS 18 rollout for M4 iPad Pro after bricking complaints

Category: Apple|Sep 20, 2024 | Author: Admin

Chinese botnet infects 260,000 SOHO routers, IP cameras with malware

Category: IT|Sep 19, 2024 | Author: Admin

HaLow Wi-Fi has now been tested at 9.9 miles — new Wi-Fi world record is a near 5X increase over previous best

Category: IT|Sep 18, 2024 | Author: Admin

Windows vulnerability abused braille “spaces” in zero-day attacks

Category: Microsoft|Sep 17, 2024 | Author: Admin

Important steps to take on your iPhone before installing Apple's latest iOS 18 to avoid any errors

Category: Apple|Sep 16, 2024 | Author: Admin

AMD hides Taiwan branding on Ryzen CPU packaging as it preps new chips for China market release

Category: IT|Sep 15, 2024 | Author: Admin

Contabo downtime analysis

Category: IT|Sep 14, 2024 | Author: Admin

Netflix will no longer provide support for iPhones and iPads running iOS 16

Category: IT|Sep 13, 2024 | Author: Admin

Google searches now link to the Internet Archive

Category: General|Sep 12, 2024 | Author: Admin

Apple ordered to pay back its illegal $14.4 billion Irish tax break

Category: Apple|Sep 11, 2024 | Author: Admin

Microsoft to start force-upgrading Windows 22H2 systems next month

Category: Microsoft|Sep 10, 2024 | Author: Admin

Mozilla extends Firefox support on unsupported Windows versions to March 2025

Category: IT|Sep 9, 2024 | Author: Admin

Apache fixes critical OFBiz remote code execution vulnerability

Category: IT|Sep 8, 2024 | Author: Admin

SonicWall SSLVPN access control flaw is now exploited in attacks

Category: IT|Sep 7, 2024 | Author: Admin

Microsoft Office 2024 to disable ActiveX controls by default

Category: Microsoft|Sep 6, 2024 | Author: Admin
more