CVE-2018-20250
Last modified
CVE-2018-20250 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.. CISA has confirmed active exploitation in the wild. EPSS estimates a 96.27% chance of exploitation in the next 30 days.
Description
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rarlab | Winrar | <= 5.61 |
References
- http://packetstormsecurity.com/files/152618/RARLAB-WinRAR-ACE-Format-Input-Validation-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.rapid7.com/db/modules/exploit/windows/fileformat/winrar_aceThird Party Advisory
- http://www.securityfocus.com/bid/106948Broken Link, Third Party Advisory, VDB Entry
- https://github.com/blau72/CVE-2018-20250-WinRAR-ACEExploit, Third Party Advisory
- https://research.checkpoint.com/extracting-code-execution-from-winrar/Exploit, Press/Media Coverage, Third Party Advisory
- https://www.exploit-db.com/exploits/46552/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/46756/Exploit, Third Party Advisory, VDB Entry
- https://www.win-rar.com/whatsnew.htmlRelease Notes
- http://packetstormsecurity.com/files/152618/RARLAB-WinRAR-ACE-Format-Input-Validation-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.rapid7.com/db/modules/exploit/windows/fileformat/winrar_aceThird Party Advisory
- http://www.securityfocus.com/bid/106948Broken Link, Third Party Advisory, VDB Entry
- https://github.com/blau72/CVE-2018-20250-WinRAR-ACEExploit, Third Party Advisory
- https://research.checkpoint.com/extracting-code-execution-from-winrar/Exploit, Press/Media Coverage, Third Party Advisory
- https://www.exploit-db.com/exploits/46552/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/46756/Exploit, Third Party Advisory, VDB Entry
- https://www.win-rar.com/whatsnew.htmlRelease Notes
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-20250US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2018-20250?
How severe is CVE-2018-20250?
How do I fix CVE-2018-20250?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-20245The LDAP auth backend (airflow.contrib.auth.backends.ldap_au…
- CVE-2018-20246Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-20247In Foxit Quick PDF Library (all versions prior to 16.12), is…7.8
- CVE-2018-20248In Foxit Quick PDF Library (all versions prior to 16.12), is…
- CVE-2018-20249In Foxit Quick PDF Library (all versions prior to 16.12), is…
- CVE-2018-2025IBM Spectrum Protect Backup-Archive Client and IBM Spectrum …4.4
- CVE-2018-20251In WinRAR versions prior to and including 5.61, there is pat…
- CVE-2018-20252In WinRAR versions prior to and including 5.60, there is an …
- CVE-2018-20253In WinRAR versions prior to and including 5.60, There is an …
- CVE-2018-2026IBM Financial Transaction Manager 3.2.1 for Digital Payments…4.3
- CVE-2018-2028IBM Maximo Asset Management 7.6 could allow a an authenticat…6.5
- CVE-2018-20298S3 Browser before 8.1.5 contains an XML external entity (XXE…
Are you affected by CVE-2018-20250?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
