[CVE-2021-35052] WinRAR’s vulnerable trialware: when free software isn’t free
swarm.ptsecurity.com | vulnerability | CVE-2021-35052 | #rce | #vulnerability-research | #cve | #mitm | #winrar
Summary
A chance find in WinRAR 5.70: its expired-trial notification window loads remote content through the legacy IE engine over HTTPS, so an attacker who can intercept traffic or spoof DNS can return a malicious redirect and achieve RCE. Tracked as CVE-2021-35052.
- Published
- Collected
Skip to content