We use cookies

We use cookies to ensure you get the best experience on our website. For more information on how we use cookies, please see our cookie policy.

Back to home

High-severity WinRAR 0-day exploited for weeks by 2 groups

Source

Ars Technica

Published

TL;DR

AI Generated

A high-severity zero-day vulnerability in WinRAR was exploited by two Russian cybercrime groups through phishing messages containing malicious archives. Security firm ESET detected the attacks on July 18 and linked them to an unknown WinRAR vulnerability affecting its 500 million users. The exploit leveraged Windows' alternate data streams to plant malicious executables in restricted directories, allowing attackers to backdoor targeted systems. ESET promptly notified WinRAR developers, leading to a fix released six days later to address the issue.