1.
A chance find in WinRAR 5.70: its expired-trial notification window loads remote content through the legacy IE engine over HTTPS, so an attacker who can intercept traffic or spoof DNS can return a malicious redirect and achieve RCE. Tracked as CVE-2021-35052.
Skip to content