Schneier on Security's Journal
 
[Most Recent Entries] [Calendar View]

Tuesday, August 19th, 2025

    Time Event
    1:47p
    Zero-Day Exploit in WinRAR File

    A zero-day vulnerability in WinRAR is being exploited by at least two Russian criminal groups:

    The vulnerability seemed to have super Windows powers. It abused alternate data streams, a Windows feature that allows different ways of representing the same file path. The exploit abused that feature to trigger a previously unknown path traversal flaw that caused WinRAR to plant malicious executables in attacker-chosen file paths %TEMP% and %LOCALAPPDATA%, which Windows normally makes off-limits because of their ability to execute code.

    More details in the article.

    << Previous Day 2025/08/19
    [Calendar]
    Next Day >>

Schneier on Security   About LJ.Rossia.org