Quade wrote:I will say I've never seen a virus that could get triggered just from unraring ...
There was that recent and surprising/alarming RAR critical vulnerability where an attacker could use archaic ACE encoding to embed
absolute paths into archives which then pretended to be RAR.
So, upon an un-RAR operation, files could get extracted/overwritten anywhere on your system that had the user's level of write access (e.g. C:\Users\Default), rather than the specified unpack directory.
Luckily, once discovered, RARLabs quickly removed this vulnerable ACE support, but I've been worried about something similar ever since.