{"id":130738,"date":"2019-02-21T18:17:21","date_gmt":"2019-02-21T17:17:21","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=130738"},"modified":"2025-07-01T22:20:04","modified_gmt":"2025-07-02T05:20:04","slug":"winrar-threat","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/winrar-threat\/","title":{"rendered":"WinRAR bug put half a billion users at risk"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-130762\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/04\/winrar_danger_700.jpg\" alt=\"winrar threat\" width=\"700\" height=\"467\" \/><\/p>\n<p>WinRAR is one of those programs that almost everybody has. Nobody can remember where the <a href=\"https:\/\/winrar.en.softonic.com\/?ex=DSK-1218.6\">file compression program<\/a> came from or how they got it, a lot of people don\u2019t even know it does, it is just there on their PC and always has been. Unfortunately, there is bad news for all of us as security experts\u00a0<a href=\"https:\/\/research.checkpoint.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Check Point<\/a>\u00a0have just found a bug that has been sitting in WinRAR for <strong>over 19 years.<\/strong><\/p>\n<h2>This WinRAR bug has put half a billion users at risk<\/h2>\n<p>The researchers at Check Point have discovered something rather disturbing. Buried in one of WinRAR\u2019s code libraries is a flaw that could allow hackers to execute a malicious code whenever a \u201cbooby-trapped\u201d file is opened with the program. What\u2019s worse about this whole thing is that the code library in question, UNACEV2.dll, hasn\u2019t been used since 2005.<\/p>\n<div class=\"sc-card-starred-link\">\r\n  <div class=\"sc-card-starred-link__body\">\r\n    <div class=\"sc-card-starred-link__row clearfix\">\r\n      <div class=\"sc-card-starred-link__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-starred-link__img\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2017\/11\/WiFi-Security-2-1024x576.jpg\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-starred-link__col-title\">\r\n        <p class=\"sc-card-starred-link__title\">How to secure your Wi-Fi network Part<\/p>\r\n        <a class=\"sc-card-starred-link__button\" href=\"https:\/\/en.softonic.com\/articles\/how-to-secure-your-wi-fi-network-part-2\" target=\"_blank\" rel=\"noopener noreferrer sponsored\">Make me safe<\/a>\r\n      <\/div>\r\n    <\/div>\r\n    <a class=\"sc-card-starred-link__link\" href=\"https:\/\/en.softonic.com\/articles\/how-to-secure-your-wi-fi-network-part-2\" target=\"_blank\" rel=\"noopener noreferrer sponsored\"><\/a>\r\n  <\/div>\r\n<\/div>\n<p><a href=\"https:\/\/research.checkpoint.com\/extracting-code-execution-from-winrar\/\" target=\"_blank\" rel=\"noopener noreferrer\">According to Check Point<\/a>, the bug meant they were able to insert a file into the Windows\u2019 startup folder. This file would then start automatically when Windows was booted and wouldn\u2019t need any sort of administrator\u2019s privileges to do so. Theoretically, <strong>this file could be used to grant any third-party full control over the victim\u2019s computer.<\/strong><\/p>\n<figure id=\"attachment_130740\" aria-describedby=\"caption-attachment-130740\" style=\"width: 700px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-130740\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/04\/fig2_uciru0.jpg\" alt=\"WinRAR screenshot\" width=\"700\" height=\"545\" \/><figcaption id=\"caption-attachment-130740\" class=\"wp-caption-text\">Image via: <a href=\"https:\/\/research.checkpoint.com\/extracting-code-execution-from-winrar\/\" target=\"_blank\" rel=\"noopener noreferrer\">Check Point<\/a><\/figcaption><\/figure>\n<p>The real shocker is just how many people could have been exposed to the vulnerability. Check Point puts the number at somewhere around <strong>500 million.<\/strong>\u00a0Yes, half a billion people could have had their computer taken over using this newly discovered WinRAR vulnerability. That means you\u2019ve probably been at risk for the last twenty years.<\/p>\n<div class=\"sc-card-starred-link\">\r\n  <div class=\"sc-card-starred-link__body\">\r\n    <div class=\"sc-card-starred-link__row clearfix\">\r\n      <div class=\"sc-card-starred-link__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-starred-link__img\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2017\/06\/seguridad-diaria-1024x576.jpg\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-starred-link__col-title\">\r\n        <p class=\"sc-card-starred-link__title\">The 7 security tips you really need to know<\/p>\r\n        <a class=\"sc-card-starred-link__button\" href=\"https:\/\/en.softonic.com\/articles\/every-day-tips-security-eng\/\" target=\"_blank\" rel=\"noopener noreferrer sponsored\">Read now<\/a>\r\n      <\/div>\r\n    <\/div>\r\n    <a class=\"sc-card-starred-link__link\" href=\"https:\/\/en.softonic.com\/articles\/every-day-tips-security-eng\/\" target=\"_blank\" rel=\"noopener noreferrer sponsored\"><\/a>\r\n  <\/div>\r\n<\/div>\n<p>If you think the fact that this bug is so old means you\u2019re in no rush to deal with it, think again. The fact that the vulnerability is now public means there is much more of a chance that hackers will try and exploit it. This doesn\u2019t mean that Check Point has acted irresponsibly by releasing the details, on the contrary, Check Point notified WinRAR about this vulnerability some time ago, and WinRAR has already taken action to fix it.<\/p>\n<figure id=\"attachment_130741\" aria-describedby=\"caption-attachment-130741\" style=\"width: 700px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-130741\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/04\/WinRAR_bug_tqp0mw.jpg\" alt=\"Demo on WinRAR bug\" width=\"700\" height=\"395\" \/><figcaption id=\"caption-attachment-130741\" class=\"wp-caption-text\">Screenshot from video demo of the bug on <a href=\"https:\/\/youtu.be\/R2qcBWJzHMo\" target=\"_blank\" rel=\"noopener noreferrer\">YouTube<\/a><\/figcaption><\/figure>\n<p><a href=\"https:\/\/www.win-rar.com\/whatsnew.html?&amp;L=0\" target=\"_blank\" rel=\"noopener noreferrer\">The WinRAR website says<\/a>, \u201cNadav Grossman from Check Point Software Technologies informed us about a security vulnerability in UNACEV2.DLL library. Aforementioned vulnerability makes possible to create files in arbitrary folders inside or outside of destination folder when unpacking ACE archives.\u201d WinRAR has since dropped the UNACEV2.dll code library and no longer supports the ACE archive format, which opened the door to nefarious action. Furthermore, WinRAR has released a patch for the problem, <a href=\"https:\/\/www.win-rar.com\/affdownload\/download.php\" target=\"_blank\" rel=\"noopener noreferrer\">WinRAR version 5.70 beta 1<\/a>, which you can <a href=\"https:\/\/www.win-rar.com\/affdownload\/download.php\" target=\"_blank\" rel=\"noopener noreferrer\">download here<\/a>.<\/p>\n<p>We highly recommend that if you have WinRAR installed on your PC, you update it immediately. Stay safe, people.<\/p>\n<div class=\"sc-related-articles-white\">\r\n<p class=\"sc-related-articles-white__title\">Social Media Security Tips and Tricks<\/p>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"How to set up two-factor authentication on Facebook\" href=\"https:\/\/en.softonic.com\/articles\/how-to-set-up-two-factor-authentication-on-facebook\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/05\/two-step-authorization-Facebook.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>How to set up two-factor authentication on Facebook<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"How to bulk delete apps and website logins on Facebook\" href=\"https:\/\/en.softonic.com\/articles\/how-to-bulk-delete-apps-and-website-logins-on-facebook\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/04\/access-app-application-267399.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>How to bulk delete apps and website logins on Facebook<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"How to manage Android permissions to prevent apps from spying on you\" href=\"https:\/\/en.softonic.com\/articles\/how-to-manage-android-permissions-to-prevent-apps-from-spying-on-you\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/02\/spy-android-1024x576.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>How to manage Android permissions to prevent apps from spying on you<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"How to find and block advertisers and apps on Facebook\" href=\"https:\/\/en.softonic.com\/articles\/how-to-find-and-block-advertisers-and-apps-on-facebook\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2016\/05\/facebook.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>How to find and block advertisers and apps on Facebook<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>This WinRAR bug has put half a billion users at risk. Here&#8217;s how to know if you&#8217;re affected.<\/p>\n","protected":false},"author":9073,"featured_media":130763,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[3250,1126,1027,1080,1052],"usertag":[839],"vertical":[],"content-category":[],"class_list":["post-130738","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectionwinrar","tag-online","tag-security","tag-windows","tag-windows-10","usertag-vpn"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/130738","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9073"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=130738"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/130738\/revisions"}],"predecessor-version":[{"id":326541,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/130738\/revisions\/326541"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/130763"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=130738"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=130738"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=130738"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=130738"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=130738"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=130738"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}