A critical old Remote Code Execution bug puts 500 million WinRAR users worldwide at risk. The vulnerability remains undetected for 19 years. Security researchers from Checkpoint published the technical details of the critical vulnerability that exists in the most popular software. The vulnerability resides in the unacev2.dll that used in handling the ACE archive extraction. The ACE file format compiled using WinACE. The path traversal vulnerability exists in. the DLL file allows plac ing the Startup folder instead of the destination folder.”]
Source: https://gbhackers.com/winrar-allows-attackers-computer/

