WinRAR Symbolic Link-Based 'Mark of the Web' Check Bypass Vulnerability

Vulnerability

A vulnerability exists in WinRAR versions prior to 7.11 that bypasses the 'Mark of the Web' security warning for files when a symbolic link pointing to an executable is opened. This flaw allows for the execution of arbitrary code if the crafted symbolic link is accessed.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution.

Remediation

Users are advised to update WinRAR to the latest version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.