Vietnam.vn - Nền tảng quảng bá Việt Nam

Hackers sell Zero Day vulnerability on WinRAR for 2 billion VND

Are you using WinRAR to extract files on a daily basis? If so, then you are sitting with millions of others in front of… an open door for hackers.

Báo Khoa học và Đời sốngBáo Khoa học và Đời sống18/07/2025

WinRAR, a popular file compression and decompression tool used on hundreds of millions of computers, is being targeted by hackers after a serious zero-day RCE (remote code execution) vulnerability was sold on the black market for up to $80,000.

The scary thing here is: this vulnerability is not a copy of an old, previously published vulnerability (CVE-2025-6218) but a completely new threat, unknown to anyone, with no patch, and still quietly existing in WinRAR versions from old to new.

One click, the whole system is in danger

This vulnerability allows an attacker to inject malicious code into the victim's system simply by… opening a "specially crafted" compressed file. No need to run the file, no need to grant permission, just double-clicking to unzip is enough for the hacker to take control.

Imagine you receive an email with a .rar file attached, and when you open it, it turns out to be... a birthday card or a contract. But in fact, in a split second, malware has been silently running in the background and breaking the security layer.

Winrar là phần mềm nén file phổ biến nhất thế giới.
Winrar is the most popular file compression software in the world .

With WinRAR being widely used, from individual users to businesses, the price of 80,000 USD (more than 2 billion VND) for this vulnerability is not expensive, it is a "rare commodity" in the underground world, and almost guarantees that the attacks will not be detected.

Vulnerability from the platform

One thing to note: this security flaw affects multiple versions of WinRAR, not just the latest one. That suggests it’s likely an architectural flaw, not simply a sloppy coding error in a recent update.

WinRAR, because it has been around for decades and has many complex features, is a "fertile ground" for bad guys to exploit.

Tin tặc rao bán lỗ hổng với giá 80.000 USD trên chợ đen. Ảnh chụp màn hình
Hackers are selling the vulnerability for $80,000 on the black market. Screenshot

​Security experts consider zero-day vulnerabilities like this a "security nightmare" because there are no signs of detection, no patches, and no traditional defenses that are effective enough. When the vulnerability is not yet public, users can only trust their fate.

What should users do?

While waiting for WinRAR developers to confirm and patch the bug, the best temporary prevention is to not open compressed files from unknown sources, especially from emails or strange links. Some emergency measures that can be applied:

- Use sandbox when opening compressed files

- Temporarily switch to another compression tool with better security controls

- Regularly update and monitor reputable security alert channels

Cybersecurity experts are closely monitoring this situation, because once the vulnerability is exploited in real-world attacks, the consequences will not stop at just a few infected computers.

Source: https://khoahocdoisong.vn/tin-tac-rao-ban-loi-zero-day-tren-winrar-voi-gia-2-ty-dong-post1555133.html


Comment (0)

No data
No data
PIECES of HUE - Pieces of Hue
Magical scene on the 'upside down bowl' tea hill in Phu Tho
3 islands in the Central region are likened to Maldives, attracting tourists in the summer
Watch the sparkling Quy Nhon coastal city of Gia Lai at night
Image of terraced fields in Phu Tho, gently sloping, bright and beautiful like mirrors before the planting season
Z121 Factory is ready for the International Fireworks Final Night
Famous travel magazine praises Son Doong cave as 'the most magnificent on the planet'
Mysterious cave attracts Western tourists, likened to 'Phong Nha cave' in Thanh Hoa
Discover the poetic beauty of Vinh Hy Bay
How is the most expensive tea in Hanoi, priced at over 10 million VND/kg, processed?

Heritage

Figure

Business

No videos available

News

Political System

Local

Product