Still using WinRAR? It has a worrying security flaw that could let hackers hijack your Windows device

 Still using WinRAR? It has a worrying security flaw that could let hackers hijack your Windows device

Published on April 7, 2025 | Category: tech

Still using WinRAR? It has a worrying security flaw that could let hackers hijack your Windows device

News
By Sead Fadilpašić published

WinRAR patch was recently released, so update now

Laptop screen with red background and a warning sign in the middle
(Image credit: Pixabay)

  • Security researchers uncover new flaw in WinRAR
  • The flaw allowed threat actors to bypass Mark of the Web and deploy malware to Windows devices without warning
  • WinRAR released a new version to fix the bug, so update now

Experts have uncovered a flaw in WinRAR which could allow threat actors to bypass the Mark of the Web (MotW) and deploy malware on people’s computers.

The vulnerability was discovered by Japanese researcher Shimamine Taihei from the Mitsui Bussan Secure Directions, and is now tracked as CVE-2025-31334, and was given a severity score of 6.8/10 (medium).

MotW is a security mechanism that displays a warning when an executable file is downloaded from the internet. It is built into Windows and serves as an additional layer of security, warning people that files downloaded from the internet might be dangerous - however, there is a way to work around the warning when a file is shared in an archived format.

Monitor your credit score with TransUnion starting at $29.95/month

Monitor your credit score with TransUnion starting at $29.95/month

TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You'll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnion’s advanced risk assessment tools.

Preferred partner (What does this mean?)

View Deal

“If symlink pointing at an executable was started from WinRAR shell, the executable Mark of the Web data was ignored,” WinRAR explained the vulnerability.

A symlink (short for symbolic link) is a shortcut or alias to a file or folder. Instead of copying a file, a symlink just points to it. Therefore, a hacker could create a symlink pointing to an executable with MotW, and if a victim runs it, the MotW wouldn’t show.

The vulnerability was found in all older versions of WinRAR, and it was addressed in version 7.11, which is now available for download.

Ever since Mark of the Web was introduced, cybercriminals have been looking for different ways to bypass it and deliver malware without warning.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

In late January 2025, 7-Zip patched a major flaw that enabled just that. It is tracked as CVE-2025-0411 and was given a high severity score, 7/10. Earlier still, in 2022, researchers found a password-protected .ZIP file with an .ISO file inside that was able to bypass MotW.

To mitigate the risk, users should always keep their archivers up to date, and be vigilant when downloading files from the internet.

Via BleepingComputer

You might also like

  • Ivanti patches serious Connect Secure flaw
  • We've rounded up the best password managers
  • Take a look at our guide to the best authenticator app
TOPICS
Sead Fadilpašić

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

More about security
Scanguard

Scanguard

The Python banner logo on a computer screen running a code editor.

Malicious Python packages are stealing vital data, and have been downloaded thousands of times already

Latest
LG C4 OLED TV in living room

Best Buy is blowing out TVs ahead of the NCAA Championship game - deals from $70

See more latest
Most Popular
The titular Thunderbolts teams standing in the building formerly known as Avengers Tower in Marvel's Thunderbolts movie
New Marvel trailer for Thunderbolts* shines a spotlight on its main villain, and he looks and sounds even worse than Thanos
The Python banner logo on a computer screen running a code editor.
Malicious Python packages are stealing vital data, and have been downloaded thousands of times already
Samsung Galaxy S25 home screen with Now Brief widget
Your Samsung Galaxy S25 just got a huge free Gemini upgrade that gives your AI assistant eyes
Characters wearing light suits in Tron: Ares
Disney's cult sci-fi saga reboot is back with a Tron: Ares trailer that sees the sequel leave the Grid
Abstract image of cyber security in action.
PoisonSeed campaign hijacks business CRM and email accounts to send out huge amounts of spam
BenQ PD2700U in a home office showing the Windows background
Windows 11’s rumored Start menu redesign could mean it eats up a huge chunk of desktop space for some users – although it can be tamed
An Nvidia GeForce RTX 4060 Ti
Keen to buy an RTX 5060 Ti? Benchmarks and more rumored sightings suggest you don’t have long to wait for Nvidia’s next GPU
Tom Cruise swings from an aeroplane undercarriage in the final Mission Impossible movie
New Mission Impossible trailer shows off Tom Cruise's latest stunts in the final chapter of Paramount's action spy series
Quordle on a smartphone held in a hand
Quordle hints and answers for Tuesday, April 8 (game #1170)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Tuesday, April 8 (game #667)

Related Articles

Spotify is about to be flooded with AI-made ads, and I wonder if it will make much of a difference to businesses

Spotify’s new AI-powered ad tool may not be the solution they claim....

Read More
CinemaCon 2025 live – first Avatar 3 reaction, juicy Fantastic Four news,

CinemaCon 2025 is officially underway – here are all new movie announc...

Read More
NYT Wordle today — answer and my hints for game #1385, Friday, April 4

Looking for Wordle hints? I can help. Plus get the answers to Wordle t...

Read More