How Unrar Handles Symlinks on Windows

When extracting archives on a Windows host, the command-line utility unrar processes symbolic links (symlinks) through a combination of operating system permission checks, file system compatibility rules, and built-in security filters. By default, unrar avoids creating native Windows symlinks to prevent potential security vulnerabilities, but it can be configured to recreate them if the underlying file system supports NTFS links and the user account holds the necessary privileges.

Windows Permissions and Filesystem Requirements

To create symbolic links on Windows, the target drive must use the NTFS file system, as FAT32 and exFAT do not support symbolic links. Additionally, the Windows security model restricts the creation of symlinks:

  • Administrator Privileges: By default, standard users cannot create symbolic links. The command prompt or terminal running unrar must be elevated to Administrator.
  • Developer Mode: On Windows 10 and Windows 11, enabling Developer Mode in system settings grants standard, unprivileged user accounts the SeCreateSymbolicLinkPrivilege, allowing unrar to generate symlinks without administrative elevation.

If unrar attempts to create a symbolic link without these permissions, the Windows API (CreateSymbolicLink) fails, and unrar reports an access denied error or falls back to standard file extraction.

The -ol Switch and Default Extraction Behavior

unrar relies on command-line switches to determine how links stored within a RAR archive are processed:

  • Default Behavior (Without -ol): When you run a standard extraction command such as unrar x archive.rar, unrar skips the creation of actual symbolic links. Instead, it extracts the target data directly (if available) or creates a small regular text file containing the target path string referenced by the symlink.
  • Link Recreation (-ol): Passing the -ol switch explicitly instructs unrar to extract symbolic links as actual links rather than regular files. For example:
    unrar x -ol archive.rar
    With this flag enabled, unrar parses the symlink metadata stored in the archive and invokes the Windows API to generate a directory symlink or file symlink corresponding to the original structure.

Security Filters and Path Traversal Protection

Archive extraction tools are common targets for directory traversal attacks, where a malicious archive contains a symlink pointing to a sensitive system location (such as C:\Windows\System32) to overwrite system files upon extraction.

To mitigate this risk on Windows:

  1. Path Sanitization: unrar strips or rejects absolute paths (e.g., C:\path) and parent directory indicators (..\) within symlink targets.
  2. Boundary Restriction: Even when the -ol switch is active, modern versions of unrar refuse to create symlinks that point outside the defined extraction root directory.
  3. Zone Identification: If an archive contains invalid or prohibited paths for Windows (such as Unix-style reserved characters like :, *, or ?), unrar skips link generation to avoid generating invalid file system entries.