3 days ago, a proof-of-concept (PoC) was published for a vulnerability in WinRAR SFX v5.21 , which is the latest version of the popular software used to compress and decompress files.
At this moment, the vulnerability is yet to be patched, so WinRAR users are advised to be extra vigilant when handling uninvited compressed SFX files. Be advised to download the new version as soon as a patch has been made available.
Granted a CVSS score of 7.4, the vulnerability could allow hackers to remotely execute system code and compromise victim machines, leading to control, surveillance and potentially data theft. A CVE score is yet to be issued.
I recommend to be careful
Read more here