{"id":25447,"date":"2019-02-20T22:06:41","date_gmt":"2019-02-20T22:06:41","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/"},"modified":"2019-02-20T22:06:41","modified_gmt":"2019-02-20T22:06:41","slug":"behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/","title":{"rendered":"Behold\u2026 a WinRAR security bug that&#8217;s older than your child&#8217;s favorite YouTuber. And yes, you should patch this hole"},"content":{"rendered":"<p>CheckPoint infosec eggheads are <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/research.checkpoint.com\/extracting-code-execution-from-winrar\/\">today laying claim<\/a> to discovering a Windows archiving security flaw that appears to have been lingering since 2005.<\/p>\n<p>The programming cockup can be potentially exploited when a user accidentally opens a malicious archive, perhaps one sent by email or downloaded from a website: unpacking it can lead to malware smuggled within the file executing on the next reboot, as a result of this flaw.<\/p>\n<p>The vulnerability itself lies in unacev2.dll, a library used to parse ACE archives, a little-used compression format that dates back to the 1990s. In practice, the vulnerability would be targeted via WinRAR or other popular archive extraction tools that include and use this wonky .dll. In other words, you get someone to open the archive in WinRAR, which passes it to the library, and then, if the stars align, your victim gets owned.<\/p>\n<p>Specifically, according to CheckPoint, an attacker can craft a poisoned ACE archive, disguised as a RAR file, that, when opened by WinRAR, exploits a path traversal flaw in unacev2.dll to trick the archiving tool into extracting the files into a path of the attacker&#8217;s choosing.<\/p>\n<p>This alone would be a potentially bad flaw but in some situations, however, the bug could pose a critical risk. The CheckPoint researchers found that while WinRAR by default does not have access to the Windows startup folder, (C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp), a second directory, at (C:\\Users\\&lt;user name&gt;\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup) was accessible. This means that an attacker who knew the user name of the target (such as in a spear-phishing situation) could get the files to extract into the startup directory and, when the PC was restarted, launch them automatically to effectively get remote code execution on the targeted machine.<\/p>\n<div class=\"promo_article\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2015\/05\/29\/kim_jong_un.jpg?x=174&amp;y=115&amp;crop=1\" width=\"174\" height=\"115\" alt=\"Kim Jong Un\"\/><\/p>\n<h2 title=\"'SiliVaccine' uses ancient, stolen, Trend Micro AV engine and bad home-brew crypto\">North Korea&#8217;s antivirus software whitelisted mystery malware<\/h2>\n<p><a href=\"https:\/\/www.theregister.co.uk\/2018\/05\/02\/north_korea_silivaccine_av_software_analysis\/\"><span>READ MORE<\/span><\/a><\/div>\n<p>Due to the age of the vulnerable component, a fix was not easy to pull off. The last commercial program to offer ACE archiving was released in 2007, and the company making that software went dark in 2017. The vulnerable .dll itself hadn&#8217;t been updated since 2005.<\/p>\n<p>Because of this, WinRAR says it is just going to drop the entire dated ACE format, killing off the vulnerability.<\/p>\n<p>&#8220;Nadav Grossman from Check Point Software Technologies informed us about a security vulnerability in UNACEV2.DLL library. Aforementioned vulnerability makes possible to create files in arbitrary folders inside or outside of destination folder when unpacking ACE archives,&#8221; <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.win-rar.com\/whatsnew.html?&amp;L=0\">WinRAR said<\/a>.<\/p>\n<p>&#8220;WinRAR used this third party library to unpack ACE archives. UNACEV2.DLL had not been updated since 2005 and we do not have access to its source code. So we decided to drop ACE archive format support to protect security of WinRAR users.&#8221;<\/p>\n<p>The ACE format has been removed in 5.70 beta 1, so all versions of WinRAR after that release will be protected from the bug. \u00ae<\/p>\n<p class=\"wptl btm\"><span>Sponsored:<\/span> <a href=\"https:\/\/go.theregister.co.uk\/tl\/1810\/-7143\/cloud-security-from-start-point-to-end-point?td=wptl1810\">Cloud Security: From Start Point to End Point<\/a><\/p>\n<p>READ MORE <a href=\"http:\/\/go.theregister.com\/feed\/www.theregister.co.uk\/2019\/02\/20\/winrar_security_bug\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Bet all two of you who paid to activate your copy are feeling a little cheesed off at this 14-year-old undetected flaw CheckPoint infosec eggheads are today laying claim to discovering a Windows archiving security flaw that appears to have been lingering since 2005.\u2026  READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":25448,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-25447","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Behold\u2026 a WinRAR security bug that&#039;s older than your child&#039;s favorite YouTuber. And yes, you should patch this hole 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Behold\u2026 a WinRAR security bug that&#039;s older than your child&#039;s favorite YouTuber. And yes, you should patch this hole 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2019-02-20T22:06:41+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"174\" \/>\n\t<meta property=\"og:image:height\" content=\"115\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Behold\u2026 a WinRAR security bug that&#8217;s older than your child&#8217;s favorite YouTuber. And yes, you should patch this hole\",\"datePublished\":\"2019-02-20T22:06:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\\\/\"},\"wordCount\":513,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/02\\\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\\\/\",\"name\":\"Behold\u2026 a WinRAR security bug that's older than your child's favorite YouTuber. And yes, you should patch this hole 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/02\\\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole.jpg\",\"datePublished\":\"2019-02-20T22:06:41+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/02\\\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/02\\\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole.jpg\",\"width\":174,\"height\":115},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Behold\u2026 a WinRAR security bug that&#8217;s older than your child&#8217;s favorite YouTuber. And yes, you should patch this hole\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Behold\u2026 a WinRAR security bug that's older than your child's favorite YouTuber. And yes, you should patch this hole 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/","og_locale":"en_US","og_type":"article","og_title":"Behold\u2026 a WinRAR security bug that's older than your child's favorite YouTuber. And yes, you should patch this hole 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2019-02-20T22:06:41+00:00","og_image":[{"width":174,"height":115,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Behold\u2026 a WinRAR security bug that&#8217;s older than your child&#8217;s favorite YouTuber. And yes, you should patch this hole","datePublished":"2019-02-20T22:06:41+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/"},"wordCount":513,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/","url":"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/","name":"Behold\u2026 a WinRAR security bug that's older than your child's favorite YouTuber. And yes, you should patch this hole 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole.jpg","datePublished":"2019-02-20T22:06:41+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole.jpg","width":174,"height":115},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/behold-a-winrar-security-bug-thats-older-than-your-childs-favorite-youtuber-and-yes-you-should-patch-this-hole\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Behold\u2026 a WinRAR security bug that&#8217;s older than your child&#8217;s favorite YouTuber. And yes, you should patch this hole"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/25447","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=25447"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/25447\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/25448"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=25447"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=25447"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=25447"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}