According to PANews, a recent security vulnerability in WinRAR has been uncovered by the Japanese security team CSIRT. This flaw allows the bypassing of Microsoft's Windows Mark of the Web (MoTW) security mechanism, potentially enabling the execution of malicious programs from the internet without user awareness. The vulnerability has been assigned the identifier CVE-2025-31334.
In response to the cybersecurity challenges posed by this WinRAR vulnerability to critical infrastructure, several technical measures are recommended. Firstly, a comprehensive inspection of computer network devices among WinRAR users should be conducted to identify those affected by the vulnerability, and the latest version should be promptly installed. Secondly, resetting the configuration of the WinRAR client is advised. Lastly, it is recommended that WinRAR users avoid connecting to untrusted networks when handling sensitive data.