SCHNEIER

Zero-Day Exploit in WinRAR File_SCHNEIER:657F9597A40B5181C2B0F0DFF8879995

Description

A zero-day vulnerability in WinRAR is being exploited by at least two Russian criminal groups:

> The vulnerability seemed to have super Windows powers. It abused alternate data streams, a Windows feature that allows different ways of representing the same file path. The exploit abused that feature to trigger a previously unknown path traversal flaw that caused WinRAR to plant malicious executables in attacker-chosen file paths %TEMP% and %LOCALAPPDATA%, which Windows normally makes off-limits because of their ability to execute code.

More details in the article.
Visit Original Source

Basic Information

ID SCHNEIER:657F9597A40B5181C2B0F0DFF8879995
Published Aug 19, 2025 at 11:07
Modified Aug 14, 2025 at 16:20

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.