Get the App
SLTechnology News&Howtos  ›  IT Information  › 

WinRAR software has been exposed to have serious security vulnerabilities. Users need to update to the latest version as soon as possible.

Shulou Source: shulou.com Published: 2023-11-24 21:21:29 10月03日 Update

Thanks to CTOnews.com netizen soft media user 1520111 for the clue delivery! CTOnews.com October 19 news, popular compressed file management software WinRAR recently discovered a serious security vulnerability, the vulnerability number CVE-2023-38831. This vulnerability allows hackers to execute arbitrary code on users 'computers using malicious files, compromising users' data and privacy security.

According to Google's Threat Analysis Group (TAG), this vulnerability has been exploited by multiple cybercrime organizations. Cybercrime organizations began exploiting the vulnerability in early 2023, when defenders were unaware of it. Currently, WinRAR has released a fix patch, but there are still many users who have not updated in time and are still in danger.

The attacker's modus operandi is to place a seemingly harmless file (such as a PNG image) in a ZIP archive and open it via WinRAR. WinRAR executes malicious code in compressed packages due to an error in Windows handling file names with spaces.

Google's update notes state,"WinRAR before version 6.23 executes 'poc.png_/poc.png_.cmd' when users double-click a file named 'poc.png_'(underlined for spaces) on WinRAR's interface. "

To protect your PC, CTOnews.com recommends downloading and installing the latest version of the software from WinRAR website as soon as possible.

Tags: Vulnerabilities users files security versions software updates code malicious computers spaces networks crime security vulnerabilities dangers underscores middle pictures multiple groups Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno MariaDB Shulou Tech Info MySQL Linux Huawei