How UnRAR Handles Windows Junction Points

This article examines how the UnRAR utility processes Windows NTFS junction points when designated as extraction targets. It covers the resolution of target paths, file-writing behavior, overwrite protections, and the built-in security mechanisms designed to mitigate path traversal risks when unpacking archives to linked directories.

Target Path Resolution

When you specify an existing Windows junction point as the extraction destination (for example, unrar x archive.rar C:\JunctionFolder\), UnRAR interacts with the Windows API to resolve the NTFS reparse point. The operating system transparently redirects write operations to the target directory mapped to that junction. As long as the executing user account has standard write permissions to the destination target, UnRAR successfully writes the extracted files to that underlying location.

Path Traversal and Security Boundaries

Modern versions of UnRAR enforce strict path canonicalization to prevent security vulnerabilities, such as arbitrary file writes via directory traversal. When extracting into a junction point:

  • Canonical Path Validation: UnRAR computes the absolute path of the destination to ensure all archived files remain confined within the extracted hierarchy.
  • Relative Path Stripping: Path elements such as ../ (parent directory traversal) within the archive are stripped or neutralized. This ensures that even if the junction points to an unexpected volume or folder, archived files cannot escape the target root.

Overwriting Existing Junctions

If an archive contains a folder whose name matches an existing junction point inside the destination folder, UnRAR applies defensive measures:

  • UnRAR will not overwrite or delete an existing junction point to replace it with an archived folder.
  • Attempting to unpack a file that collides with an existing reparse point typically triggers a file-creation error or a collision warning, preventing redirection attacks where a malicious actor uses pre-created junctions to divert written files.

UnRAR differentiates between the destination path itself and junctions defined inside the RAR archive:

  • By default, directory junctions and symbolic links contained within the archive are either skipped or extracted as standard empty directories to prevent symlink-based privilege escalation.
  • Processing link definitions within the archive requires explicit command-line flags, such as -ol (extract symbolic links as links) or -ola (allow absolute path links, where permitted by permissions). Even with these flags enabled, UnRAR restricts junction creation if it detects that the link points outside the designated extraction base folder.