this? Sort of. In Windows, an archive within an archive within an archive wouldn’t be flagged as a “file downloaded from the internet” so could be executed without malware checks. It’s a windows-specific issue and is only an issue if you’re downloading an untrusted archive from the internet. It’s patched in the latest version.
Didn’t 7-zip have a vulnerability a while back?
this? Sort of. In Windows, an archive within an archive within an archive wouldn’t be flagged as a “file downloaded from the internet” so could be executed without malware checks. It’s a windows-specific issue and is only an issue if you’re downloading an untrusted archive from the internet. It’s patched in the latest version.
Yeah, WinRAR averages about 3 per year.
All software stacks are going to be vulnerable in some way or another. We don’t have a way to create perfect software just yet.