Files could be dropped into the Windows Startup folder .

When a user opens "22793.rar" (or similar ACE-based exploits):

The flaw existed in unacev2.dll , a third-party library WinRAR used to unpack files. Path Traversal: Attackers could bypass folder restrictions.

Share