Monday, November 4, 2024
HomeComputer Security19-Year-Old Vulnerability in WinRAR Allows Attackers to Get Complete Control over victim’s...

19-Year-Old Vulnerability in WinRAR Allows Attackers to Get Complete Control over victim’s Computer

Published on

Malware protection

A critical old Remote Code Execution bug puts 500 million WinRAR users worldwide at risk. The vulnerability remains undetected for 19 years.

Security researchers from Checkpoint published the technical details of the critical vulnerability that exists in the most popular software.

Based on the crash tests researchers detected an old DLL library that compiled back in 2006 without any validation mechanism.”After researching this behavior, we found a logical bug: Absolute Path Traversal. From this point on it was simple to leverage this vulnerability to remote code execution.”

- Advertisement - SIEM as a Service

The vulnerability resides in the unacev2.dll that used in handling the ACE archive extraction. The ACE file format compiled using WinACE.

The path traversal vulnerability exists in the DLL file allows placing the Startup Folder instead of the destination folder.

Researchers changed the .ace extension to .rar extension as the WinRAR detects the file based on content and not by the formats. This makes the malicious executable to trigger automatically on system reboot.

Once the malware executed the attackers can gain access to complete control over the computer. Here is the POC published by Checkpoint research.

“We can gain code execution, by extracting a compressed executable file from the ACE archive to one of the Startup Folders. Any files that reside in the Startup folders will be executed at boot time.”

The vulnerability has fixed with WinRAR version 5.70 beta 1 as the ACE archive format not supported anymore.

Here you can find the complete technical analysis which is done by the checkpoint security researchers.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Millions of Devices Found Running Outdated Versions of the Famous Softwares

Hackers Exploiting Adobe Flash Zero-Day that Launching via a Microsoft Office Document

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Evasive Panda Attacking Cloud Services To Steal Data Using New Toolkit

The Evasive Panda group deployed a new C# framework named CloudScout to target a...

Massive Midnight Blizzard Phishing Attack Using Weaponized RDP Files

Researchers warn of ongoing spear-phishing attacks by Russian threat actor Midnight Blizzard targeting individuals...

Sophisticated Phishing Attack Targeting Ukraine Military Sectors

The Ukrainian Cyber Emergency Response Team discovered a targeted phishing campaign launched by UAC-0215...

Chinese Hackers Attacking Microsoft Customers With Sophisticated Password Spray Attacks

Researchers have identified a network of compromised devices, CovertNetwork-1658, used by Chinese threat actors...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Evasive Panda Attacking Cloud Services To Steal Data Using New Toolkit

The Evasive Panda group deployed a new C# framework named CloudScout to target a...

Massive Midnight Blizzard Phishing Attack Using Weaponized RDP Files

Researchers warn of ongoing spear-phishing attacks by Russian threat actor Midnight Blizzard targeting individuals...

Sophisticated Phishing Attack Targeting Ukraine Military Sectors

The Ukrainian Cyber Emergency Response Team discovered a targeted phishing campaign launched by UAC-0215...