The developers of WinRAR have released a new version of this archiver utility for the Windows operating system, which has already fixed a critical vulnerability that allowed hackers to run arbitrary code on victims' computers and take control of the computer.

As reported by Bleeping Computer, an independent information security researcher of the Zero Day Initiative, known by the nickname goodbyeselene, discovered this vulnerability back on June 8, 2023. The vulnerability received the code name CVE-2023-40477 and a criticality score of 7.8 out of 10 possible points.

CVE-2023-40477 works like this: first, the malicious RAR file is sent to the victim, after which the cybercriminal just has to wait for the recipient to open the file. The arbitrary code is executed automatically immediately when the file is opened.

To protect against this type of attack, the user should install WinRAR version 6.23, which was released on August 2 of this year. The developers decided to release information about the problem only now that the problem has already been fixed.

There is currently no information about users affected by CVE-2023-40477.

Earlier it became known that information security specialists of Trend Micro and Fortinet companies discovered a new virus called Big Heat. It disguises itself as a Windows update, locks the computer and demands a ransom from the victim.