https://technet.microsoft.com/en-us/library/security/ms14-064.aspx
Even if unpatched, this Windows OLE vulnerability does not introduce
new risk factors for WinRAR SFX archives.
Please read http://rarlab.com/vuln_sfx_html2.htm for more details.
No patches for WinRAR are needed.
2. “Import/Export” commands:
a) WinRAR performs the additional validation of Settings.reg contents
for “Import settings from file” command to prevent importing Registry
keys unrelated to WinRAR settings;
b) WinRAR specifies the full path to regedit.exe tool to prevent
running copies of “regedit” from other folders.
3. Bugs fixed:
a) If ‘file’ and ‘file.exe’ were present in the same folder
and user double clicked on ‘file’, WinRAR could start ‘file.exe’
instead;
b) “Generate report” command could create a report in wrong folder,
not that with selected files;
c) RAR could crash when unpacking .rar archives with corrupt file
headers. Fixed now.
2. Fewer password requests in following cases in “Convert archives”
command:
a) if “Convert archives” is applied to archive with encrypted
file names, which contents is currently displayed in WinRAR;
b) if archive produced by “Convert archives” includes encrypted
file names.
3. Bugs fixed:
a) RAR volumes renamed from standard .part1.rar, .part2.rar to
.001, .002 are recognized and processed correctly now.
Previous beta opened them as set of usual split files,
not as RAR volumes;
b) reports produced with “Generate report” command contained invalid
CRC32 checksums for non-archived files;
c) “rar x arcname.rar d:” command unpacks files to d: current folder.
Previous version unpacked them to d: root folder;
d) archive comment was not encrypted if added to archive with
encrypted headers using “c” command without -hp switch.
This beta encrypts an archive comment in such case.