← All articles

WinRAR, the tool to update

A known WinRAR vulnerability still shows up in booby-trapped attachments. Here's how to close that entry point with minimal effort.

A 19-year-old vulnerability was recently discovered in WinRAR. Nineteen years is older than some of the employees on your IT team. And yet the tool keeps running, unnoticed, on thousands of workstations in small and medium businesses - a bit like that network printer nobody dares to unplug.

WinRAR, a tool we forget because it works too well

WinRAR is one of those applications you install once and never think about again. It decompresses not only ZIP archives, but also RAR files (Roshal Archive Compressed, its own format) and about fifteen other formats. As a result, it sits on a significant share of business workstations, often installed by default, rarely updated, and almost never monitored.

That's exactly the kind of tool that becomes a problem over time. Not because it's poorly built, but because it's invisible in security inventories. Software nobody thinks to update is software that quietly accumulates vulnerabilities while no one notices.

The ACE format, the entry point nobody was watching for

Among the formats WinRAR can open is ACE. ACE archives are rarely used today and lost much of their popularity in the early 2000s. The format has practically become a digital relic.

That's precisely what makes it appealing to attackers: few people are wary of it, few filtering tools block it by default, and a 19-year-old vulnerability in how WinRAR handles it has just come to light. Since then, several attackers have been sending infected ACE archives, betting that some users are still running a version of WinRAR that was never updated.

The logic is simple and remarkably effective: an employee receives an email with an attachment that looks like an ordinary compressed file, opens it out of habit, and an old bug in an old format does the rest. No password to crack, no firewall to bypass. It just takes one person, on one outdated workstation, opening the wrong file.

Three concrete actions, in order

First, update WinRAR across all your workstations. This is the simplest and most decisive step: an up-to-date version eliminates the vulnerability at the source. It's also worth checking the other compression/decompression tools installed across your environment, since WinRAR isn't the only application exposed to this kind of long-standing flaw.

Second, set an explicit filter for .ACE extensions on your email filtering platforms. Since this format is rarely used legitimately in a business context, blocking it at the gate removes a good chunk of the risk without disrupting day-to-day operations. It's the kind of rule you configure once and that keeps working for you continuously.

Third, and perhaps most important, remind your users never to open unknown or suspicious attachments. No update and no filter can replace an employee who takes two seconds to ask whether an email actually makes sense before clicking.

An old vulnerability, a very current risk

What makes this story worth telling is how well it illustrates the way cybersecurity actually works in a business. The problem is almost never the latest trendy piece of software. It's the application that's been installed for years, the one nobody questions because it just quietly does its job. A vulnerability can lie dormant for nearly two decades before being actively exploited - which means software inventory and regular updates aren't a one-time task, but a discipline to maintain over the long run.

That's exactly the kind of oversight MMO Techno builds into its cybersecurity support: keeping an eye on the tools running quietly in the background of your organization, making sure critical updates get applied, and setting up the right filtering rules before an old bug turns into a very real incident.

An IT project or a question?

Talk to an MMO Techno expert. We'll give you a clear, fast answer.

Contact us