Earlier quoted context omitted.
I'll happily wait for someone else to open that archive and let us know whats in the folder. Somehow feels like a great way to get a bunch of people to download a rar with a zero day
Yes, an example: https://blog.google/threat-analysis-group/government-backed-... I also do not understand how Anonymous would sift through 10TB to confirm the validity of the claims.
So the vulnerability is not in WinRAR, but rather in the ShellExecute windows code that desperately tries to find something else to run when asked to execute a file that does not exist.
As my security officer says at $dayJob, "having a security hole there for thirty years does not make it somehow less of a security hole".