Junglewise Threat Intelligence

CVE-2018-20250: WinRAR Absolute Path Traversal Vulnerability

CVE-2018-20250 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-02-15

Technologies: RARLAB WinRAR. Vendors: RARLAB.

Executive brief

A path traversal vulnerability exists in WinRAR's UNACEV2.dll when processing the ACE archive format. By manipulating the filename field with specific patterns, an attacker can bypass the intended destination folder and treat the filename as an absolute path, potentially leading to remote code execution.

Affected products

  • RARLAB WinRAR prior to and including 5.61

Timeline

  • 2019-02-05: disclosed: Initial discovery/disclosure by Check Point Research
  • 2022-02-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats