← Back

CVE-2018-20250

nvd nist
Published: Feb 5, 2019Modified: Oct 31, 2025CISA KEV

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

Affected (1)

Products: Rarlab: Winrar
1 product
Winrar
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 5.61

References (17)

Source: cve@checkpoint.com
Broken LinkThird Party AdvisoryVDB Entry
Source: cve@checkpoint.com
ExploitThird Party Advisory
Source: cve@checkpoint.com
ExploitPress/Media CoverageThird Party Advisory
Source: cve@checkpoint.com
ExploitThird Party AdvisoryVDB Entry
Source: cve@checkpoint.com
ExploitThird Party AdvisoryVDB Entry
Source: cve@checkpoint.com
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPress/Media CoverageThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.