{"id":140512,"date":"2015-10-01T08:07:57","date_gmt":"2015-10-01T06:07:57","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=140512"},"modified":"2015-10-01T08:09:08","modified_gmt":"2015-10-01T06:09:08","slug":"critical-vulnerability-in-winrar-exposed","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/140512-critical-vulnerability-in-winrar-exposed.html","title":{"rendered":"Critical vulnerability in WinRAR exposed"},"content":{"rendered":"<p><a href=\"http:\/\/seclists.org\/fulldisclosure\/2015\/Sep\/106\" target=\"_blank\"><strong>An independent vulnerability laboratory researcher has discovered<\/strong><\/a> a code execution vulnerability in WinRAR software.<\/p>\n<p>The vulnerability allows remote attackers to execute system-specific code to compromise a target system.<\/p>\n<p>The issue is located in the &#8216;Text and Icon&#8217; function of the &#8216;Text to display in SFX window&#8217; module.<\/p>\n<p>Remote attackers are able to generate their own compressed archives with malicious payloads to execute system-specific codes.<\/p>\n<p>The security risk of the code execution vulnerability is estimated as critical, with a CVSS (common vulnerability scoring system) count of 9.2.<\/p>\n<p>The video below shows a proof of concept on how the vulnerability can be exploited.<\/p>\n<p><iframe loading=\"lazy\" src=\"https:\/\/www.youtube.com\/embed\/fo0l0oT4468\" width=\"630\" height=\"473\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<h3 class=\"my-4\">More on security<\/h3>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/135794-a-new-ddos-reflection-attack-portmapper.html\">A new DDoS Reflection Attack: Portmapper<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/134976-large-ddos-attacks-often-use-syn-and-udp-vectors.html\">Large DDoS attacks often use SYN and UDP vectors<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/130644-massive-increase-in-ddos-attacks.html\">Massive increase in DDoS attacks<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A remote code execution vulnerability has been discovered in WinRAR, exposing 500 million users to a possible attack.<\/p>\n","protected":false},"author":23,"featured_media":140514,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[36,33154,33152],"class_list":["post-140512","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-active","tag-security-vulnarability","tag-winrar"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/140512"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=140512"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/140512\/revisions"}],"predecessor-version":[{"id":140520,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/140512\/revisions\/140520"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/140514"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=140512"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=140512"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=140512"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}