Re: WinRAR SFX v5.21 – Remote Code Execution Vulnerability

Posted by Hernan Moller on Oct 05

In fact, a SXF file type can only try to access a specific URL
(server’s attacker). Then the attacker exploits a
Microsoft’s vulnerability (ms14-064).

The WinRAR file doesn’t allow RCE by itself.

Leave a Reply