Zero-Day Exploit in WinRAR File
WinRAR零日漏洞被俄罗斯犯罪团伙利用,通过滥用Windows替代数据流功能触发路径遍历漏洞,在受限系统路径%TEMP%和%LOCALAPPDATA%植入恶意程序。 2025-8-19 11:7:28 Author: www.schneier.com(查看原文) 阅读量:19 收藏

A zero-day vulnerability in WinRAR is being exploited by at least two Russian criminal groups:

The vulnerability seemed to have super Windows powers. It abused alternate data streams, a Windows feature that allows different ways of representing the same file path. The exploit abused that feature to trigger a previously unknown path traversal flaw that caused WinRAR to plant malicious executables in attacker-chosen file paths %TEMP% and %LOCALAPPDATA%, which Windows normally makes off-limits because of their ability to execute code.

More details in the article.

Tags: , , ,

Posted on August 19, 2025 at 7:07 AM0 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.


文章来源: https://www.schneier.com/blog/archives/2025/08/zero-day-exploit-in-winrar-file.html
如有侵权请联系:admin#unsafe.sh