Critical Vulnerability Found in WinRAR Could Affect Millions of Users

Advertisement
By Manish Singh | Updated: 30 September 2015 18:58 IST

A security vulnerability has been found in WinRAR, a file archiver and compressor utility for Windows that is estimated to be used by more than half a billion users. The vulnerability, if exploited, allows remote attackers to execute system specific code to compromise a computer.

A proof-of-concept exploit for WinRAR SFX v5.21 has been published. Iranian researcher Mohammad Reza Espargham reported the vulnerability to Full Disclosure, a popular forum for disclosure of security information. "The vulnerability allows unauthorised remote attackers to execute system specific code to compromise a target system," he said.

Advertisement

The vulnerability is said to affect all versions of WinRAR SFX, making its users extremely prone to attacks. Security firm MalwareBytes has independently confirmed the existence of the critical vulnerability in the said application.

The vulnerability, if exploited, allows a remote attacker to execute malicious code when a victim tries to unzip an SFX archive file, a type of RAR file that is often used to safeguard executable files. "Basically, the attack uses the option to write HTML code in the text display window when creating a SFX archive," writes MalwareBytes.

Advertisement

What makes the vulnerability, which has been flagged as critical, even more alarming is the fact that it requires very low user interaction. If the affected file is open, the malware could compromise the device or network. As of now, the vulnerability is yet to be patched.

Which is why you should be extra careful while handling any SFX archive, and probably not open an SFX file that you have received from an untrusted source. This is a good rule to follow for any file on the Internet of course, and even more so for self-executing files like exe and SFX. WinRAR developer RAR Labs in the meantime has responded to the issue, and said, "Executable files are potentially dangerous by design. Run them only if they are received from a trustworthy source. WinRAR self-extracting (SFX) archives are not less or more dangerous than other exe files."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. These OnePlus Smartphones Could Receive the ColorOS 17 Update in India
  2. OnePlus N6x Design, Colour Options Teased Ahead of India Launch
  3. Tecno Camon 50 Ultra 5G Sale Begins in India Today
  4. Samsung Galaxy Unpacked Event Today: How to Watch Livestream
  5. Redmi Note 17 Pro Max Listed on NBTC Website Ahead of Imminent Launch
  6. Xiaomi Pad 9 Could Launch Soon After Clearing Key Certification Hurdle
  1. Vivo S2 India Launch Reportedly On the Horizon as Promotional Poster Leaks
  2. Samsung Galaxy Unpacked Event Today: How to Watch Galaxy Z Fold 8 Ultra, Galaxy Z Flip 8, Galaxy Watch 9 Launch Live
  3. Offline UPI Payments With NFC Support Could Launch in India Soon
  4. Samsung Galaxy S26 Ultra's Privacy Display Feature Gets a Major Upgrade in One UI 9 Beta
  5. OnePlus N6x Design, Colour Options Teased in New Marketing Material Ahead of Imminent Launch in India
  6. OnePlus 11, Nord 4, and Newer Models Tipped to Receive the Android 17-Based ColorOS 17 Update in India
  7. Redmi Note 17 Pro Max Appears on Thailand's NBTC Certification Database, Might Launch Soon
  8. Apple’s First Foldable iPhone Reportedly Appears in iOS 27 Beta Code With a Multi-Battery Setup
  9. X for Android App Undergoes Major Design Overhaul, Enhanced Performance and Reliability
  10. Samsung Galaxy Buds Able to Reportedly Skip Galaxy Unpacked Launch; Could Debut in October
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.