Executive brief
A path traversal vulnerability exists in WinRAR's UNACEV2.dll when processing the ACE archive format. By manipulating the filename field with specific patterns, an attacker can bypass the intended destination folder and treat the filename as an absolute path, potentially leading to remote code execution.
Affected products
- RARLAB WinRAR prior to and including 5.61
Timeline
- 2019-02-05: disclosed: Initial discovery/disclosure by Check Point Research
- 2022-02-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog