logo

Zero-Day Exploit in WinRAR File

ID: 3e864bb4-5885-5dde-8860-3350265b0040

STIX ID: report--3e864bb4-5885-5dde-8860-3350265b0040

Feed Name: Schneier on Security

Threat Score
85/100

Date Published: 2025-08-19

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

A zero-day WinRAR vulnerability is being actively exploited by at least two Russian criminal groups; the exploit abuses Windows alternate data streams and a path traversal flaw to plant malicious executables in %TEMP% and %LOCALAPPDATA%, allowing attacker-chosen code execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.