Stembolt WinRAR flaw bypasses Windows Mark of the Web security alerts A vulnerability in the WinRAR file archiver solution could be exploited to bypass the Mark of the Web (MotW) security warning and execute arbitrary code on a Windows machine. The security issue is tracked as CVE-2025-31334 and affects all WinRAR versions except the most recent release, which is currently 7.11.
SpHeRe31459 It’s interesting that 7-Zip also had a flaw recently (back in January) fixed that allowed Mark of the Web bypass. I’m guessing hunting for MoW bypasses must be a hot new thing for researchers and threat actors right now. https://www.bleepingcomputer.com/news/security/7-zip-fixes-bug-that-bypasses-the-windows-motw-security-mechanism-patch-now/
GeekGirl1 SpHeRe31459 - Thanks! Your post caused me to check my 7-Zip. As the article states, 7-Zip doesn’t have an auto-update feature. Yup, my version was from 2020. 😦 I’m now at the latest 7-Zip 24.09.
antdude GeekGirl1 Thanks! Your post caused me to check my 7-Zip. As the article states, 7-Zip doesn’t have an auto-update feature. Yup, my version was from 2020. 😦 I’m now at the latest 7-Zip 24.09. Check this forum often and you will see someone posting about a new version. 😉