WinRAR, the popular file compression program, has a security vulnerability that allows attackers to execute remote code on a user's computer when opening an SFX file (self-extracting archive).

The bug was discovered by Mohammad Reza Espargham from Vulnerability Lab, as well as Pieter Arntz from Malwarebytes.
According to both reports, the bug only affects the latest version of WinRaR, 5.21, and can be exploited by any attacker who manages to place malicious HTML code inside the “Text to display in SFX window” section when creating a new SFX archive.
After the file is sent to a victim, each time the file is launched, the malicious code is executed and, depending on the attacker's skill, could compromise the system, network, or even the device. Attackers do not require special privileges on the target machine to exploit this vulnerability.
Because RAR and SFX files are used on a daily basis by a large number of users, hackers have a high probability of exploiting this flaw out there.
A video – proof of vulnerability – is the one below by Mohammad Reza Espargham.
