End of an Era: Microsoft's Integration Spells Trouble for WinRAR
The Story
Microsoft announced in May 2023 that Windows 11 would natively open RAR files along with tar, gz, and 7z archives by integrating the open source libarchive project, ending a 28 year wait since the RAR format arrived as a DOS program in 1995.
Microsoft shipped support in its October 2023 KB5031455 update, letting File Explorer read RAR and other archives, but excluding password encrypted files.
The move was widely read as a blow to WinRAR, the long dominant commercial compression utility generations of users installed specifically for RAR handling.
WinRAR's team responded graciously, saying it felt honored by Microsoft's decision and hoped the change would make RAR compression even more popular and accessible to users unfamiliar with WinRAR.
The company also acknowledged the competitive pressure, saying it needed to keep developing WinRAR to make it even more attractive, pointing to the new WinRAR 6.22 beta and a major upgrade planned for the end of 2023.
Built in extraction removed a common reason to install another utility, while encrypted archives remained outside the feature Microsoft shipped.
Microsoft shipped support in its October 2023 KB5031455 update, letting File Explorer read RAR and other archives, but excluding password encrypted files.
The move was widely read as a blow to WinRAR, the long dominant commercial compression utility generations of users installed specifically for RAR handling.
WinRAR's team responded graciously, saying it felt honored by Microsoft's decision and hoped the change would make RAR compression even more popular and accessible to users unfamiliar with WinRAR.
The company also acknowledged the competitive pressure, saying it needed to keep developing WinRAR to make it even more attractive, pointing to the new WinRAR 6.22 beta and a major upgrade planned for the end of 2023.
Built in extraction removed a common reason to install another utility, while encrypted archives remained outside the feature Microsoft shipped.
Why It Matters
Native extraction does not patch a separate copy of WinRAR. ESET documented RomCom exploiting CVE-2025-8088 in July 2025; WinRAR 7.13 fixed that path traversal flaw on July 30. A different problem later reached the recovery tools: RARLAB says version 7.23 fixed a heap overflow in RAR5 recovery volume reconstruction affecting WinRAR, RAR and UnRAR, but not UnRAR.dll, which lacks that feature. These are distinct bugs with different affected components, not evidence that every older installation has been compromised. Administrators inherit the maintenance work; check the installed component against the developer's current release notes before processing archives from an unfamiliar sender.
Go Deeper
Read the original reporting at TechCrunch.
Read Full Story at TechCrunch →