New Update WinRAR - Updates Thread

WinRAR 7.11 (stable version)
WinRAR - What's new in the latest version

Version 7.11

1. If "Add to archive..." Explorer context menu command is applied to
multiple archives in the disk root, for example, d:\arc1.rar
and d:\arc2.rar, WinRAR will propose arc1_rar.rar default name
for a new archive. Previous version proposed arc1.rar, updating one
of selected archives instead of creating a new one.

2. Bugs fixed:

a) WinRAR 7.10 failed to update solid archives containing a folder
record placed before a file record. It issued the checksum error
message and aborted processing.

As a result of this fix, this version preserves the original position
of such folders after updating and doesn't move them to the end
of archive as WinRAR 7.10 did;

b) when extracting a file from CAB archive over an existing file,
existing files were overwritten, but not truncated.
So if existing file was larger than extracted, existing file data
had been left at the end of the extracted file;

c) if SFX module from "Advanced SFX options" dialog was stored
in the compression profile, it was applied as is, even if archive
format was changed after selecting the profile. It could result
in SFX module mismatching the archive format;

d) choosing a value in bytes from drop down list associated
with archive dialog "Split to volumes, size" field didn't set
units to bytes automatically;

e) if SFX "TextDone" command was used together with "Silent"
and "TempMode" commands, the completion message was sometimes
displayed behind other opened windows;

f) if symlink pointing at an executable was started from WinRAR shell,
the executable Mark of the Web data was ignored. We are thankful
to Shimamine Taihei of Mitsui Bussan Secure Directions, Inc
for reporting this issue.
Source: WinRAR archiver, a powerful tool to process RAR and ZIP files

Download: WinRAR and RAR archiver downloads
 
WinRAR 7.12 beta 1
Version 7.12 beta 1

1. When extracting a file, previous versions of WinRAR, Windows versions
of RAR, UnRAR, portable UnRAR source code and UnRAR.dll can be tricked
into using a path, defined in a specially crafted archive,
instead of user specified path.

Unix versions of RAR, UnRAR, portable UnRAR source code
and UnRAR library, also as RAR for Android, are not affected.

We are thankful to whs3-detonator working with Trend Micro Zero Day
Initiative for letting us know about this security issue.


2. Previously "Generate report" command included archived file names
into HTML report as is, allowing to inject potentially unsafe HTML tags
into the report. To prevent such injection the current version replaces
< and > file name characters in HTML report with < and > strings.

We are thankful to Marcin Bobryk (github.com/MarcinB44) for bringing
this security issue to our attention.


3. If "Test archived files" and "recovery volumes" archiving options
are used together, recovery volumes are also tested. Previous versions
completed the test before creating recovery volumes, so they hadn't
been verified.

4. Nanosecond file time precision is preserved for Unix file records
when modifying RAR archive in Windows. Previously it was converted
to Windows 100 nanosecond precision.
Source: WinRAR archiver, a powerful tool to process RAR and ZIP files

Download: WinRAR and RAR archiver downloads
 
WinRAR 7.12 (stable)
Version 7.12

1. When extracting a file, previous versions of WinRAR, Windows versions
of RAR, UnRAR, portable UnRAR source code and UnRAR.dll can be tricked
into using a path, defined in a specially crafted archive,
instead of user specified path.

Unix versions of RAR, UnRAR, portable UnRAR source code
and UnRAR library, also as RAR for Android, are not affected.

We are thankful to whs3-detonator working with Trend Micro Zero Day
Initiative for letting us know about this security issue.

2. Previously "Generate report" command included archived file names
into HTML report as is, allowing to inject potentially unsafe HTML tags
into the report. To prevent such injection the current version replaces
< and > file name characters in HTML report with < and > strings.

We are thankful to Marcin Bobryk (github.com/MarcinB44) for bringing
this security issue to our attention.

3. If "Test archived files" and "recovery volumes" archiving options
are used together, recovery volumes are also tested. Previous versions
completed the test before creating recovery volumes, so they hadn't
been verified.

4. Nanosecond file time precision is preserved for Unix file records
when modifying RAR archive in Windows. Previously it was converted
to Windows 100 nanosecond precision.
Source: WinRAR archiver, a powerful tool to process RAR and ZIP files

Download: WinRAR and RAR archiver downloads
 

WinRAR 7.13 Beta 1​

Version 7.13 beta 1

1. Another directory traversal vulnerability, differing from that
in WinRAR 7.12, has been fixed.

When extracting a file, previous versions of WinRAR, Windows versions
of RAR, UnRAR, portable UnRAR source code and UnRAR.dll can be tricked
into using a path, defined in a specially crafted archive,
instead of user specified path.

Unix versions of RAR, UnRAR, portable UnRAR source code
and UnRAR library, also as RAR for Android, are not affected.

We are thankful to Anton Cherepanov, Peter Kosinar, and Peter Strycek
from ESET for letting us know about this security issue.

2. Bugs fixed:

a) WinRAR 7.12 "Import settings from file" command failed to restore
settings, saved by WinRAR versions preceding 7.12;

b) WinRAR 7.12 set a larger than specified recovery size for compression
profiles, created by WinRAR 5.21 and older.
Source: WinRAR archiver, a powerful tool to process RAR and ZIP files

Download: WinRAR and RAR archiver downloads
 
WinRAR 7.13 (stable release)
Version 7.13

1. Another directory traversal vulnerability, differing from that
in WinRAR 7.12, has been fixed.

When extracting a file, previous versions of WinRAR, Windows versions
of RAR, UnRAR, portable UnRAR source code and UnRAR.dll can be tricked
into using a path, defined in a specially crafted archive,
instead of user specified path.

Unix versions of RAR, UnRAR, portable UnRAR source code
and UnRAR library, also as RAR for Android, are not affected.

We are thankful to Anton Cherepanov, Peter Kosinar, and Peter Strycek
from ESET for letting us know about this security issue.

2. Bugs fixed:

a) WinRAR 7.12 "Import settings from file" command failed to restore
settings, saved by WinRAR versions preceding 7.12;

b) WinRAR 7.12 set a larger than specified recovery size for compression
profiles, created by WinRAR 5.21 and older.
Source: WinRAR archiver, a powerful tool to process RAR and ZIP files

Download: WinRAR and RAR archiver downloads
 
Update your WinRAR because hackers are using this flaw to sneak malware onto your PC
Last week, WinRAR 7.13 dropped with a fix for a directory traversal vulnerability tracked as CVE-2025-8088. We now have more details on the exploit, thanks to work by researchers from ESET who discovered that attackers were actively abusing the flaw.

The vulnerability exists within UNRAR.dll, a core library handling archive extraction. Attackers craft a malicious archive that can then trick the software into writing a file to a location they choose, instead of the directory a user selects.
As Bleeping Computer notes, WinRAR has no built-in automatic update mechanism, so anyone using the software needs to manually visit the official site and install version 7.13 to be protected. The WinRAR devs claim that Unix versions of RAR and UnRAR, along with RAR for Android, are not affected.
 
WinRAR 7.20 Beta 1
Version 7.20 beta 1

1. Performance improvements when deleting files in solid RAR archives:

a) if there are no non-zero files after deleted files, archive
recompressing isn't performed;

b) part of archive before deleted files is copied as is, without
repacking. Its contents is unpacked to memory if necessary,
but not recompressed;

c) semi-solid archive processing involves only solid blocks containing
deleted files. Unaffected solid blocks are copied as is.

2. "Generate archive name by mask" archiving option and -ag command line
switch:

a) new 'K' format character defines the current day of week
name as a text string;

b) new 'O' format character defines the current month name as a text
string regardless of format character number. Unlike "MMM" mask,
it allows to use shorter or longer than 3 character names,
such as -agOO;

c) excessive format characters exceeding the available field width
are now ignored instead of appending to archive name.
So it is possible to use full month or week day names by providing
format characters in the amount equal or exceeding the longest name,
such as -agKKKKKKKKKK for day of week names.

3. Command line -s switch:

a) switch -s accepts the optional parameter preceded by '=' character.

Switches -s, -se, -sv, -sv-, -s- are replaced by -s=f, -s=e,
-s=v, -s=d, -s=-. Previous versions of these switches are still
supported in the current version, but can be removed in the future.

It is allowed to combine multiple modifiers in the same switch,
such as -s=e100f.

b) new switch -s=r resets the solid statistics before adding new files
to existing archive.

4. Switch -tk now accepts the optional date parameter in YYYYMMDDHHMMSS
format. If used without parameter when modifying an archive,
it preserves the original archive time. If optional parameter
is present, it is assigned to archive modification time.

It is allowed to insert separators like '-' or ':' to the date string
and omit trailing fields. For example, switch -tk2025-06-01 is correct.

5. "Specified time" is added to "Set archive time to" options on "Time"
page of archiving dialog. It allows to assign the manually entered time
to newly created or modified archives.

6. UTF-8 output format and byte order mask options are added to
"Generate report" command.

7. "Cloud files" option is added to "Where to check for SFX archives"
group in "Settings/Integration/Context menu items..." dialog.

If this option is off, WinRAR shell extension will not attempt
to detect if archive is self-extracting, when right clicking
an executable cloud file not available locally. This detection
involves data read and can be slow for such files.

This option relies on file attributes returned by a cloud storage
provider and can be ignored if required attribute isn't supported
by specific cloud service.

8. "Copy to clipboard" button at the bottom of "Search results" dialog
places current results of "Find files" command to clipboard.

9. It takes less time to open a large archive with a lot of files
and folders in WinRAR file list. This is most noticeable for ZIP
archives containing millions of files.

10. Improved extraction speed of TAR and TAR based archives,
such as .tar.gz or tar.xz. It is most visible for hard disk drives
with slower seek time and large archives containing a lot of files.

11. SFX module sets sfxnamenoext environment variable, containing
SFX archive name without path and extension. It allows to append
the archive name to user defined destination path like:

Path=c:\Util\%sfxnamenoext%"

12. "minsize" parameter, defining the minimum file reference size
in -oi[0-4][:] switch, now can include an optional trailing
unit size character. So -oi:1m is the equivalent of -oi:1048576.

13. Switch -x recognizes exclude paths with both Windows and Unix style
path separators, so -xfolder\file and -xfolder/file do the same.
Previously only -xfolder\file excluded the file.

14. Bugs fixed:

a) "Files to exclude" field of archiving dialog was ignored for all
but first ZIP archives if "Put each file to separate archive"
option was turned on;

b) when processing "Convert archives" command, "Use for all archives"
option in the password prompt was available only for encrypted
archives with file name encryption and couldn't be enabled
when converting archives without encrypted file names.
Source: WinRAR archiver, a powerful tool to process RAR and ZIP files

Download: WinRAR and RAR archiver downloads
 
WinRAR 7.20 Beta 3
Version 7.20 beta 3

1. Original and packed file size column widths in "l" and "v" commands
are increased by 1 symbol, so 10 digit file sizes are also displayed
aligned by these commands.

2. If "Reuse existing window" option is enabled when opening an archive,
but another WinRAR copy is busy with archive processing, the archive
is opened by current copy. Previously neither of copies opened it.

3. Bugs fixed:

a) previous beta failed to open archives in ZIP format with extra fields
shorter than 4 bytes, such as some APK files;

b) "Ask" option in WinRAR "Settings/Viewer/Viewer type" didn't display
the viewer type prompt for PNG files and several other image formats;

c) -ag switch 'k' modifier used English week day names even
in localized versions.
WinRAR archiver, a powerful tool to process RAR and ZIP files

Download: WinRAR and RAR archiver downloads
 
WinRAR 7.20 (stable release)

Version 7.20

1. Performance improvements when deleting files in solid RAR archives:

a) if there are no non-zero files after deleted files, archive
recompressing isn't performed;

b) part of archive before deleted files is copied as is, without
repacking. Its contents is unpacked to memory if necessary,
but not recompressed;

c) semi-solid archive processing involves only solid blocks containing
deleted files. Unaffected solid blocks are copied as is.

2. "Generate archive name by mask" archiving option and -ag command line
switch:

a) new 'K' format character defines the current day of week
name as a text string;

b) new 'O' format character defines the current month name as a text
string regardless of format character number. Unlike "MMM" mask,
it allows to use shorter or longer than 3 character names,
such as -agOO;

c) excessive format characters exceeding the available field width
are now ignored instead of appending to archive name.
So it is possible to use full month or week day names by providing
format characters in the amount equal or exceeding the longest name,
such as -agKKKKKKKKKK for day of week names.

3. Command line -s switch:

a) switch -s accepts the optional parameter preceded by '=' character.

Switches -s, -se, -sv, -sv-, -s- are replaced by -s=f, -s=e,
-s=v, -s=d, -s=-. Previous versions of these switches are still
supported in the current version, but can be removed in the future.

It is allowed to combine multiple modifiers in the same switch,
such as -s=e100f.

b) new switch -s=r resets the solid statistics before adding new files
to existing archive.

4. Switch -tk now accepts the optional date parameter in YYYYMMDDHHMMSS
format. If used without parameter when modifying an archive,
it preserves the original archive time. If optional parameter
is present, it is assigned to archive modification time.

It is allowed to insert separators like '-' or ':' to the date string
and omit trailing fields. For example, switch -tk2025-06-01 is correct.

5. "Specified time" is added to "Set archive time to" options on "Time"
page of archiving dialog. It allows to assign the manually entered time
to newly created or modified archives.

6. UTF-8 output format and byte order mark options are added to
"Generate report" command.

7. "Cloud files" option is added to "Where to check for SFX archives"
group in "Settings/Integration/Context menu items..." dialog.

If this option is off, WinRAR shell extension will not attempt
to detect if archive is self-extracting, when right clicking
an executable cloud file not available locally. This detection
involves data read and can be slow for such files.

This option relies on file attributes returned by a cloud storage
provider and can be ignored if required attribute isn't supported
by specific cloud service.

8. "Copy to clipboard" button at the bottom of "Search results" dialog
places current results of "Find files" command to clipboard.

9. It takes less time to open a large archive with a lot of files
and folders in WinRAR file list. This is most noticeable for ZIP
archives containing millions of files.

10. Improved extraction speed of TAR and TAR based archives,
such as .tar.gz or tar.xz. It is most visible for hard disk drives
with slower seek time and large archives containing a lot of files.

11. SFX module sets sfxnamenoext environment variable, containing
SFX archive name without path and extension. It allows to append
the archive name to user defined destination path like:

Path=c:\Util\%sfxnamenoext%"

12. "minsize" parameter, defining the minimum file reference size
in -oi[0-4][:] switch, now can include an optional trailing
unit size character. So -oi:1m is the equivalent of -oi:1048576.

13. Switch -x recognizes exclude paths with both Windows and Unix style
path separators, so -xfolder\file and -xfolder/file do the same.
Previously only -xfolder\file excluded the file.

14. Bugs fixed:

a) "Files to exclude" field of archiving dialog was ignored for all
but first ZIP archives if "Put each file to separate archive"
option was turned on;

b) when processing "Convert archives" command, "Use for all archives"
option in the password prompt was available only for encrypted
archives with file name encryption and couldn't be enabled
when converting archives without encrypted file names.

 
Last edited by a moderator:

You may also like...