Author Topic: Vulnerability in RAR program  (Read 1465 times)

0 Members and 1 Guest are viewing this topic.

Offline vonegood

  • Newbie
  • *
  • Posts: 5
Vulnerability in RAR program
« on: March 16, 2019, 08:49:49 PM »
Hi guys,

There was vulnerability of RAR, and was used to extract malware to startup folder without user's knowledge. The malware was distributed in pirate copy of "Ariana_Grande-thank_u,_next(2019)_[320].rar"

When a vulnerable version of WinRAR is used to extract the contents of this archive, a malicious program is extracted to Startup folder behind the scenes. User Access Control (UAC) is bypassed, so no alert is displayed to the user. The next time the system restarts, the malware (exe file) is run.

My question is, why is UAC bypassed and how it is possible? How is it possible when you use user account? Isn't it Microsoft bug?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Vulnerability in RAR program
« Reply #1 on: March 16, 2019, 09:13:03 PM »
Upload and scan file at www.virustotal.com

Post link to scan result here



Offline vonegood

  • Newbie
  • *
  • Posts: 5
Re: Vulnerability in RAR program
« Reply #2 on: March 16, 2019, 09:39:32 PM »
This is now what I asked about. I dont have this file. I am just asking here.

 “User Access Control (UAC) is bypassed after the payload gets executed, so no alert is displayed to the user. The next time the system restarts, the malware is run.”

How is it possible that UAC is bypassed?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Vulnerability in RAR program
« Reply #3 on: March 16, 2019, 09:51:14 PM »
I guess it is this

Over 100 Exploits Found for 19-Year Old WinRAR RCE Bug
https://www.bleepingcomputer.com/news/security/over-100-exploits-found-for-19-year-old-winrar-rce-bug/

https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/attackers-exploiting-winrar-unacev2-dll-vulnerability-cve-2018-20250/



Not detected by avast - Ariana_Grande-thank_u,_next(2019)_[320].rar - 2019-03-16 20:57:33 UTC
https://www.virustotal.com/#/file/e6e5530ed748283d4f6ef3485bfbf84ae573289ad28db0815f711dc45f448bec/detection

First Submission   2019-02-28 08:26:51
Last Submission           2019-02-28 08:26:51
Last Analysis           2019-03-16 20:57:33





Extracted Malware payload Not detected by avast -    2019-03-16 20:52:33 UTC
https://www.virustotal.com/#/file/a1c06018b4e331f95a0e33b47f0faa5cb6a084d15fec30772923269669f4bc91/detection

First Submission   2019-02-28 08:49:53
Last Submission           2019-02-28 08:49:53
Last Analysis           2019-03-16 20:52:33





« Last Edit: March 16, 2019, 10:01:57 PM by Pondus »

Offline vonegood

  • Newbie
  • *
  • Posts: 5
Re: Vulnerability in RAR program
« Reply #4 on: March 16, 2019, 09:57:16 PM »
Yes, you are right. And how is it possible that UAC is bypassed here? Please answer this.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Vulnerability in RAR program
« Reply #5 on: March 16, 2019, 10:09:28 PM »