4 ms·
> The exploit abused that feature to trigger a previously unknown path traversal flaw that caused WinRAR to plant malicious executables in attacker-chosen file
by pityJuke 1y ago
> The exploit abused that feature to trigger a previously unknown path traversal flaw that caused WinRAR to plant malicious executables in attacker-chosen file paths %TEMP% and %LOCALAPPDATA%, which Windows normally makes off-limits because of their ability to execute code.
This seems... wrong? Isn't %LOCALAPPDATA% commonly used to store executables for programs that want to install for a single user and not the whole computer? An example of which includes Google Chrome?
- jeroenhd 1y agoESET's story seems to make more sense: https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/ https://www.welivesecurity.com/en/eset-research/update-winra... The exploit abuses ADSes with ..\ in the name to drop files on the system that aren't visible in the WinRAR file browser. It drops malware in the temp directory and then a .lnk in the Startup directory to activate an attack against COM, influencing the DLL that's being loaded by legitimate applications.
- dataflow 1y ago> This seems... wrong? Isn't %LOCALAPPDATA% commonly used to store executables for programs that want to install for a single user and not the whole computer? An example of which includes Google Chrome? Maybe you're thinking of %AppData%?
- gruez 1y agoNo, he's right. >By default, VS Code is installed under C:\Users\{Username}\AppData\Local\Programs\Microsoft VS Code. https://code.visualstudio.com/docs/setup/windows https://code.visualstudio.com/docs/setup/windows %appdata% would be C:\Users\{Username}\AppData\Roaming
- wongarsu 1y ago%LocalAppData% is for files you wouldn't want to synchronize across multiple computers using the same account. Installed programs squarely fall into that category, even just based on size. %AppData% is also commonly used to install executables, but I'd consider that a bug. Just like putting your cache dir in %appdata% instead of %localappdata%
- rkagerer 1y agoThe only reason publishers use those appdata paths for executables is so regular users can install their software without needing an administrator or a UAC prompt, since Microsoft locked down installing to the various Program Files directories.
- wongarsu 1y agoBut %localappdata% has all the same advantages and permissions. Using %appdata% for executables is usually a mix of ignorance and indifference. Roaming user profiles are a rare setup nowadays and are even less common on developer machines. And it's not like it breaks in obvious ways, the is just more storage space used and login is slower because more data is transferred from the server, in a setup that devs and PMs don't use