For years, this was one of the most "reliable" ways for hackers to infect systems because: Users generally trust .rar files.
The flaw existed in unacev2.dll , a third-party library WinRAR used to unpack files. Path Traversal: Attackers could bypass folder restrictions.
WinRAR failed to properly sanitize these paths, allowing the file to be written outside the intended extraction folder. ⚠️ Security Implications
RARLAB removed unacev2.dll entirely to fix the issue.