• News/
  • https://www.bleepingcomputer.com/news/security/winrar-flaw-bypasses-windows-mark-of-the-web-security-alerts/

WinRAR flaw bypasses Windows Mark of the Web security alerts

BleepingComputer
·
Ionut Ilascu
·
Published Apr 5, 2025
·
Updated

A vulnerability in the WinRAR file archiver solution could be exploited to bypass the Mark of the Web (MotW) security warning and execute arbitrary code on a Windows machine. The security issue is tracked as CVE-2025-31334 and affects all WinRAR versions except the most recent release, which is currently 7.11. Mark of the Web is a security function in Windows in the form of a metadata value (an alternate data stream named ‘zone-identifier’) to tag as potentially unsafe files downloaded from the internet. When opening an executable with the MotW tag, Windows warns the user that it was downloaded from the internet and could be harmful and offers the option to continue execution or terminate it.

The CVE-2025-31334 vulnerability can help a threat actor bypass the MotW security warning when opening a symbolic link (symlink) pointing to an executable file in any WinRAR version before 7.11. An attacker could execute arbitrary code by using a specially crafted symbolic link. It should be noted that a symlink can be created on Windows only with administrator permissions. The security issue received a medium severity score of 6.8 and has been fixed in the latest version of WinRAR, as noted in the applications change log: “If symlink pointing at an executable was started from WinRAR shell, the executable Mark of the Web data was ignored” - WinRAR The vulnerability was reported by Shimamine Taihei of Mitsui Bussan Secure Directions through the Information Technology Promotion Agency (I...

Read full article

Affected Software

2 affected components
WinRAR=7.10
WinRAR
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a vulnerability in WinRAR that allows attackers to bypass Windows' Mark of the Web security alerts.

2

What security implications are discussed?

The vulnerability could enable the execution of arbitrary code on Windows machines, posing a significant security risk.

3

What specific vulnerability is tracked in the article?

The security issue is tracked as CVE-2025-31334.

4

Which versions of WinRAR are affected by this vulnerability?

The flaw affects all versions of WinRAR, specifically mentioned is version 7.10.

5

What is the core functionality that the vulnerability impacts in WinRAR?

The vulnerability impacts the ability of Windows to provide security alerts related to the Mark of the Web.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203