Close Menu
Technotification
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Technotification
    • Home
    • News
    • How To
    • Explained
    • Facts
    • Lists
    • Programming
    • Security
    • Gaming
    Technotification
    Home › Security › 19-Year-Old WinRar Flaw Left Millions of Users Vulnerable

    19-Year-Old WinRar Flaw Left Millions of Users Vulnerable

    By Subham KapisweDecember 3, 2022
    Facebook Twitter Reddit LinkedIn
    19-Year-Old WinRar Flaw Left Millions of Users Vulnerable

    WinRar is one of the most popular utility software used to view, create, extract archives in multiple formats like ZIP, RAR, etc. The program is quite useful and people have been using it for more than two decades. However, a recent bug in this software has questioned the security of this popular program in various ways.

    As per a report by security research company Check Point, Winrar has a serious security flaw that has remained unfixed since 2005. The bug creates a loophole that can be used by black hat hackers to plant malware within your system and gain full access.

    The bug was Found During a Fuzz Test

    winrar screenshot

    The vulnerability is found during a fuzz test performed by the company. If you don’t know, fuzz tests are actually a part of stress testing, where people feed random data to the software to test the limit and provoke software crashing.

    The flaw provides attackers full privilege to extract .exe files into the startup folder of a computer. In this way, they ensure that the programs will automatically run at the time of booting the computer.

    Going a little deeper, the researchers have found that the bug was actually caused by an Old DLL (Dynamic Link Library) that was used to process files compressed in ACE format.

    The vulnerability has actually put millions of users around the world at risk. The bug seems even threatening after knowing the fact that malicious ACE archive can be renamed into RAR format without losing the exploit.

    Also Read: 10 Types of Viruses That Can Harm Your Computer or Smartphone

    How to be Safe?

    After explaining the bug through a blog post, WinRar has taken immediate action and fixed the vulnerability by removing support for the ACE format. If you are a Winrar user, you must update to the latest version (5.70 beta 1) released by the company the last month.

    After this step, it seems that the Winrar was using a third-party tool for ACE archives which wasn’t updated since 2005. Anyway, 19 years is a pretty long time and you should feel responsible for users who believe you and using your products.

    Share. Facebook Twitter LinkedIn Tumblr Reddit Telegram WhatsApp
    Subham Kapiswe
    • LinkedIn

    A computer science engineer by education and blogger by profession who loves to write about Programming, Cybersecurity, Blockchain, Artificial Intelligence, Open Source and other latest technologies.

    Related Posts

    NVIDIA GeForce NOW is Finally Coming to India

    January 8, 2025

    The Psychology of a Phishing Email: How Scammers Play with Your Mind

    July 16, 2024

    9 Essential Elements of a Strong Cyber Security Management System

    July 3, 2024

    Common Cyber Attacks and How to Prevent Them

    July 3, 2024

    How Cyber Security Paid Training Prepares You for Real-World Threats

    June 13, 2024

    The Role of Security in Server Colocation Environments

    March 12, 2024
    Lists You May Like

    10 Best RARBG Alternative Sites in April 2025 [Working Links]

    April 1, 2025

    The Pirate Bay Proxy List in 2025 [Updated List]

    January 2, 2025

    10 Sites to Watch Free Korean Drama [2025 Edition]

    January 2, 2025

    10 Best Torrent Search Engine Sites (2025 Edition)

    February 12, 2025

    10 Best GTA V Roleplay Servers in 2025 (Updated List)

    January 6, 2025

    5 Best Torrent Sites for Software in 2025

    January 2, 2025

    1337x Alternatives, Proxies, and Mirror Sites in 2025

    January 2, 2025

    10 Best Torrent Sites for eBooks in 2025 [Working]

    January 2, 2025

    10 Best Anime Torrent Sites in 2025 [Working Sites]

    January 6, 2025

    Top Free Photo Editing Software For PC in 2025

    January 2, 2025
    Pages
    • About
    • Contact
    • Privacy
    • Careers
    Privacy

    Information such as the type of browser being used, its operating system, and your IP address is gathered in order to enhance your online experience.

    © 2013 - 2025 Technotification | All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.