﻿{"id":506,"date":"2019-02-26T13:10:19","date_gmt":"2019-02-26T19:10:19","guid":{"rendered":"https:\/\/www.uv.mx\/csirt\/?p=506"},"modified":"2019-02-26T17:13:03","modified_gmt":"2019-02-26T23:13:03","slug":"26-022019-exploit-aprovecha-vulnerabilidad-de-winrar","status":"publish","type":"post","link":"https:\/\/www.uv.mx\/csirt\/boletines\/vulnerabilidades\/26-022019-exploit-aprovecha-vulnerabilidad-de-winrar\/","title":{"rendered":"26\/02\/2019 Exploit aprovecha vulnerabilidad de WinRAR"},"content":{"rendered":"<p>&nbsp;<\/p>\n<div style=\"width: 752px;max-width: 752px;height: auto;border: 1px solid #369;margin: 0px auto;background-color: #fff\">\n<p><img decoding=\"async\" style=\"width: 750px\" src=\"http:\/\/boletines.uv.mx\/images\/images\/boletin-encabezado.jpg\" alt=\"\" \/><\/p>\n<table style=\"width: 100%\" border=\"0\" cellspacing=\"1\" cellpadding=\"1\" align=\"center\">\n<tbody>\n<tr>\n<td><img decoding=\"async\" style=\"width: 190px;height: 25px\" src=\"http:\/\/boletines.uv.mx\/images\/images\/cintillo_informativo.jpg\" alt=\"\" \/><\/td>\n<td style=\"text-align: right\"><span style=\"font-size: 18px\"><span style=\"color: #666666\"><span style=\"font-family: tahoma,geneva,sans-serif\">26 de febrero de 2019<\/span><\/span><\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr \/>\n<div style=\"background-color: #e6e6e6;line-height: 1.4\"><strong>Exploit aprovecha vulnerabilidad de WinRAR <\/strong><\/div>\n<div style=\"background-color: #e6e6e6;line-height: 1.4\">ID: 26021912<\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<hr \/>\n<\/div>\n<div style=\"background-color: #f5f5f5;line-height: 1.4\">\n<p><span style=\"color: #28519b\"><span style=\"font-size: 16px\"><strong>Descripci\u00f3n<\/strong><\/span><\/span><\/p>\n<p style=\"text-align: justify\">Investigadores de <em>360 Threat Intelligence\u00a0Center<\/em> dieron a conocer a trav\u00e9s de su cuenta de Twitter, el hallazgo de un exploit que intenta instalar un backdoor en el equipo, \u00a0tras descubrir en un correo electr\u00f3nico que se estaba distribuyendo un archivo RAR, que trata de aprovecharse de este fallo descubierto en WinRAR.<\/p>\n<p style=\"text-align: justify\">\u00abEl exploit intenta extraer un archivo en la carpeta de inicio C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\,\u00a0una vez extra\u00eddo el achivo CMSTray.exe, la pr\u00f3xima vez que se inicie el equipo se ejecutar\u00e1 y copiar\u00e1 a %Temp%\\ para luego ejecutar el archivo wbssrv.exe\u00bb &#8211;<strong>BleepingComputer<\/strong>.<\/p>\n<p style=\"text-align: center\"><img decoding=\"async\" style=\"width: 301px;height: 366px\" src=\"http:\/\/boletines.uv.mx\/images\/images\/Captura%20de%20pantalla%202019-02-26%20a%20la(s)%2012.52.24.png\" alt=\"\" \/><\/p>\n<\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<p><span style=\"color: #28519b\"><strong><span style=\"font-size: 16px\">Productos afectados<\/span><\/strong><\/span><\/p>\n<\/div>\n<div style=\"background-color: #8cc63f;line-height: 1.4\">\n<p>&nbsp;<\/p>\n<\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<ul>\n<li>WinRAR<\/li>\n<\/ul>\n<hr size=\"2\" \/>\n<\/div>\n<div style=\"background-color: #f5f5f5;line-height: 1.4\">\n<p><span style=\"color: #28519b\"><span style=\"font-size: 16px\"><strong>Recomendaci\u00f3n:<\/strong><\/span><\/span><\/p>\n<p style=\"text-align: justify\">Se recomienda a los usuarios de Windows que hagan uso de este compresor de archivos, actualizar a la \u00faltima versi\u00f3n 5.70 que corrige este fallo.<\/p>\n<p>Para m\u00e1s informaci\u00f3n:<\/p>\n<p><a href=\"https:\/\/www.winrar.es\/descargas\">https:\/\/www.winrar.es\/descargas<\/a><\/p>\n<p><a href=\"https:\/\/securityaffairs.co\/wordpress\/81669\/hacking\/winrar-exploit-malspam.html\">https:\/\/securityaffairs.co\/wordpress\/81669\/hacking\/winrar-exploit-malspam.html <\/a><\/p>\n<\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<hr \/>\n<\/div>\n<p><img decoding=\"async\" style=\"width: 750px;height: 120px\" src=\"http:\/\/boletines.uv.mx\/images\/images\/cintillo_inferior.jpg\" alt=\"\" \/><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; 26 de febrero de 2019 Exploit aprovecha vulnerabilidad de WinRAR ID: 26021912 Descripci\u00f3n Investigadores de 360 Threat Intelligence\u00a0Center dieron a conocer a trav\u00e9s de su cuenta de Twitter, el hallazgo de un exploit que intenta instalar un backdoor en el equipo, \u00a0tras descubrir en un correo electr\u00f3nico que se estaba distribuyendo un archivo RAR, [&hellip;]<\/p>\n","protected":false},"author":2037,"featured_media":456,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ventana_nueva":"","tipo_url":"","url":"","extracto":"","imagen_halign":"","imagen_valign":"","bg_size":"","text_hide":"","media_url":"","tipo_media":"","video_url":"","video_pos":"","video_youtube":"","footnotes":""},"categories":[18,15],"tags":[],"class_list":["post-506","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-informativos","category-vulnerabilidades"],"_links":{"self":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/posts\/506","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/users\/2037"}],"replies":[{"embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/comments?post=506"}],"version-history":[{"count":0,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/posts\/506\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/media\/456"}],"wp:attachment":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/media?parent=506"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/categories?post=506"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/tags?post=506"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}