Man-in-the-Middle (MitM) attack in WinRAR - CVE-2021-35052
Published: October 22, 2021 / Updated: November 29, 2021
WinRAR
RARLAB
Description
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists in the WinRar due to usage of Microsoft Internet Explorer component to display a trial notification message in a pop-up window. A remote attacker with ability to perform ARP-spoofing attack can supply a malicious file (e.g. a .rar file) to the WinRar application.