New WinRAR 7.23 Includes Security Fixes and Library Updates

The update focuses on security hardening.

WinRAR, the archiving utility used on millions of Windows PCs, has shipped version 7.23. The update focuses on security hardening rather than new user-facing features, but it's worth installing promptly given the nature of the fixes.

What's New

  • Heap overflow fix: A heap overflow vulnerability in the RAR5 recovery volume data reconstruction code has been patched. This affected WinRAR, RAR, and UnRAR.
  • Path traversal protection: Previously, a specially crafted RAR archive could create a symbolic link pointing outside the destination folder even without the -ola switch. Extraction code now includes additional checks that block files from being placed in such folders, closing off a path traversal attack vector.
  • Updated 7z library: The bundled 7zxa.dll 7-Zip extraction library has been updated to version 26.02, pulling in upstream bug and vulnerability fixes.
  • Command-line tweak: The -iver switch now prints the RAR version even when -idc is set (via command line, configuration file, or the RARINISWITCHES environment variable), and its output now ends with a newline character.

Why It Matters

Archive-handling security bugs are a common vector for malicious files disguised as harmless downloads. Given WinRAR's massive install base, updating promptly closes off a known exploitation path.

Download

Get the latest version from the official WinRAR site. You can also find version details and history on UpdateStar.

about author