CVE-2018-20251
Last modified
CVE-2018-20251 is a vulnerability of currently unknown severity. In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNACEV2.dll) creates files and folders as written in the filename field even when WinRAR validator noticed the traversal attempt and requestd to abort the extraction process. EPSS estimates a 31.53% chance of exploitation in the next 30 days.
Description
In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNACEV2.dll) creates files and folders as written in the filename field even when WinRAR validator noticed the traversal attempt and requestd to abort the extraction process. the operation is cancelled only after the folders and files were created but prior to them being written, therefore allowing the attacker to create empty files and folders everywhere in the file system.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rarlab | Winrar | <= 5.61 |
References
- http://www.securityfocus.com/bid/106948Third Party Advisory, VDB Entry
- https://research.checkpoint.com/extracting-code-execution-from-winrar/Exploit, Third Party Advisory
- https://www.win-rar.com/whatsnew.htmlRelease Notes, Vendor Advisory
- http://www.securityfocus.com/bid/106948Third Party Advisory, VDB Entry
- https://research.checkpoint.com/extracting-code-execution-from-winrar/Exploit, Third Party Advisory
- https://www.win-rar.com/whatsnew.htmlRelease Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20251?
How severe is CVE-2018-20251?
How do I fix CVE-2018-20251?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-20246Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-20247In Foxit Quick PDF Library (all versions prior to 16.12), is…7.8
- CVE-2018-20248In Foxit Quick PDF Library (all versions prior to 16.12), is…
- CVE-2018-20249In Foxit Quick PDF Library (all versions prior to 16.12), is…
- CVE-2018-2025IBM Spectrum Protect Backup-Archive Client and IBM Spectrum …4.4
- CVE-2018-20250In WinRAR versions prior to and including 5.61, There is pat…7.8
- CVE-2018-20252In WinRAR versions prior to and including 5.60, there is an …
- CVE-2018-20253In WinRAR versions prior to and including 5.60, There is an …
- CVE-2018-2026IBM Financial Transaction Manager 3.2.1 for Digital Payments…4.3
- CVE-2018-2028IBM Maximo Asset Management 7.6 could allow a an authenticat…6.5
- CVE-2018-20298S3 Browser before 8.1.5 contains an XML external entity (XXE…
- CVE-2018-20299An issue was discovered in several Bosch Smart Home cameras …9.8
Are you affected by CVE-2018-20251?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
