Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2021-35052] WinRAR’s vulnerable trialware: when free software isn’t free

swarm.ptsecurity.com | vulnerability | CVE-2021-35052 | #rce | #vulnerability-research | #cve | #mitm | #winrar

Summary

A chance find in WinRAR 5.70: its expired-trial notification window loads remote content through the legacy IE engine over HTTPS, so an attacker who can intercept traffic or spoof DNS can return a malicious redirect and achieve RCE. Tracked as CVE-2021-35052.
Published
Collected

original ↗

Related coverage

back