Moneycontrol PRO
Sansaar
HomeNewsTechnologyWinRAR fixes 19-year-old bug which exposed 500 million users

WinRAR fixes 19-year-old bug which exposed 500 million users

Before the update, WinRAR was using a third-party tool to unzip ACE files which had not been updated since 2005.

February 22, 2019 / 18:07 IST

Since its launch in the late 1990s, WinRAR has remained one of the most popular software used to open compressed files. Not only could the software be used to zip or unzip files in various formats including .zip .rar .7Z .ISO but it does all this and more absolutely free of cost. While it is not totally free as users would still be prompted to purchase a copy, all one had to do was click on ‘Next Time’.

While many considered this a boon, a recent report suggests every time one clicks on ‘Next Time’, the user is exposing his computer to hackers who could use the opportunity to access their system.

According to the report published by Check Point Research, over 500 million have been using the software for over 19 years while there was a serious security exploit.

The report says, the bug in WinRAR’s extention file lets hackers to rename an ACE file which in turn allows hackers have access to the computer’s startup folder and install a program. Once the program was installed, it would run automatically when your system booted.

The researchers in their blog post have explained how they discovered the bug and also uploaded a short video to educate users about how the exploit worked.

After the researchers informed WinRAR about the critical bug, the software company was quick to respond. They patched the exploit by releasing a software update with the version 5.70 beta 1 which supports ACE archives.

Before this update, WinRAR was using a third-party tool to unzip ACE files which had not been updated since 2005.

WinRAR stated that the bug was not attacked and there were no reports of the same. However, it is alarming that the virus went unnoticed for almost two decades which could have potentially exposed data of over 500 million users.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Pranav Hegde
first published: Feb 22, 2019 06:07 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347