Welcome to our

Cyber Security News Aggregator

.

Cyber Tzar

provide a

cyber security risk management

platform; including automated penetration tests and risk assesments culminating in a "cyber risk score" out of 1,000, just like a credit score.

Zero-Day Exploit in WinRAR File

published on 2025-08-19 11:07:28 UTC by Bruce Schneier
Content:

A zero-day vulnerability in WinRAR is being exploited by at least two Russian criminal groups:

The vulnerability seemed to have super Windows powers. It abused alternate data streams, a Windows feature that allows different ways of representing the same file path. The exploit abused that feature to trigger a previously unknown path traversal flaw that caused WinRAR to plant malicious executables in attacker-chosen file paths %TEMP% and %LOCALAPPDATA%, which Windows normally makes off-limits because of their ability to execute code.

More details in the article.

Article: Zero-Day Exploit in WinRAR File - published 2 months ago.

https://www.schneier.com/blog/archives/2025/08/zero-day-exploit-in-winrar-file.html   
Published: 2025 08 19 11:07:28
Received: 2025 08 19 11:19:36
Feed: Schneier on Security
Source: Schneier on Security
Category: Cyber Security
Topic: Cyber Security
Views: 8

Custom HTML Block

Click to Open Code Editor