Warning: Critical WinRAR Flaw Affects All Versions Released In Last 19

Page 1 of 2 12 LastLast
    Warning: Critical WinRAR Flaw Affects All Versions Released In Last 19

    Warning: Critical WinRAR Flaw Affects All Versions Released In Last 19


    Last Updated: 22 Feb 2019 at 10:14

    Beware Windows users... a new dangerous remote code execution vulnerability has been discovered in the WinRAR software, affecting hundreds of millions of users worldwide.

    Cybersecurity researchers at Check Point have disclosed technical details of a critical vulnerability in WinRAR—a popular Windows file compression application with 500 million users worldwide—that affects all versions of the software released in last 19 years.

    The flaw resides in the way an old third-party library, called UNACEV2.DLL, used by the software handled the extraction of files compressed in ACE data compression archive file format.

    However, since WinRAR detects the format by the content of the file and not by the extension, attackers can merely change the .ace extension to .rar extension to make it look normal.


    Source: Warning: Critical WinRAR Flaw Affects All Versions Released In Last 19 Years
    Golden's Avatar Posted By: Golden
    21 Feb 2019


  1. Posts : 10
    Win8.1
       #1

    So I presume if you rename or delete UNACEV2.DLL in the WinRAR install folder WinRAR will not be vulnerable anymore?
      My Computer


  2. Posts : 308
    Win10
       #2

    Tovad said:
    So I presume if you rename or delete UNACEV2.DLL in the WinRAR install folder WinRAR will not be vulnerable anymore?
    Thanks for the tip, I'm secure now. I can't remember the last time I saw a *.ace file anyhow???
      My Computer


  3. Posts : 346
    Windows 10 Pro 64bit 21H2 (19043.1348)
       #3

    I have version 5.61 and that .dll file isn't in the folder at all. Lucky me :)
      My Computer


  4. Posts : 237
    windows 10 Build 20215
       #4

    Has been removed in Version 5.70.
      My Computers


  5. Posts : 308
    Win10
       #5

    I'm still running WinRAR v4.0, never saw the need to upgrade???
      My Computer


  6. Posts : 10,311
    Wndows 10 Pro x64 release preview channel
       #6

    WinRAR have fixed the flaw in the latest beta releases.
      My Computer


  7. Posts : 16
    win 10
       #7

    I have 5.40 and I deleted that .dll and the Ace32Loader.exe also. The 5.70 is a beta version and it s only in english language so I prefer not update to that
      My Computer


  8. Posts : 10,311
    Wndows 10 Pro x64 release preview channel
       #8

    mary7 said:
    I have 5.40 and I deleted that .dll and the Ace32Loader.exe also. The 5.70 is a beta version and it s only in english language so I prefer not update to that
    No, 5.70 beta1 and beta2 is available in a few languages.

    WinRAR archiver, a powerful tool to process RAR and ZIP files
      My Computer


  9. Posts : 10,311
    Wndows 10 Pro x64 release preview channel
       #9

    WinRAR 5.70 final has been released. The flaw is fixed.

    WinRAR archiver, a powerful tool to process RAR and ZIP files
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 17:17.
Find Us




Windows 10 Forums