Thursday, March 7, 2019

WinRAR critical bug being exploited in the wild


Do you love downloading subtitles (mostly compressed file WinRAR) then read this.

Are you using WinRAR in compressing or decompressing files? Is it updated or not? We all know that WinRAR is not a free software. It has expiration but even if your winrar is already expired you can still use it right? I have this one too.

I got received an email notice regarding a WinRAR bug. According to Check Point Cyber Security Team they found a critical bug that is being actively use or exploited rather in the wild. Hackers are exploiting this bug and researchers are not sure when this exploitation started.

According to them the bug reside on this dynamic link library (.dll) named UNACEV2.dll. Check you WinRAR version if this file exist. If it does, then you need to uninstall the WinRAR and after that download the latest version which does not exclude or not using the said DLL file.



Researchers found a "Absolute Path Traversal". They explain that the said bug allows the hacker to drop malicious script into windows startup that runs after reboot. This malicious file can be a backdoor or a script that allows the hacker to control your computer remotely.

One thing, all past or old version of WinRAR are affected by this bug. You need to download the latest version of WinRAR to protect yourself or your data.

Thank you for reading this. Have a great day.




PS: For more detailed explaination read this source.

No comments:

Post a Comment