CVE-2018-20252
Last modified
CVE-2018-20252 is a vulnerability of currently unknown severity. In WinRAR versions prior to and including 5.60, there is an out-of-bounds write vulnerability during parsing of crafted ACE and RAR archive formats. Successful exploitation could lead to arbitrary code execution in the context of the current user.. EPSS estimates a 3.62% chance of exploitation in the next 30 days.
Description
In WinRAR versions prior to and including 5.60, there is an out-of-bounds write vulnerability during parsing of crafted ACE and RAR archive formats. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rarlab | Winrar | <= 5.60 |
References
- http://www.securityfocus.com/bid/106948Third Party Advisory, VDB Entry
- https://research.checkpoint.com/extracting-code-execution-from-winrar/Exploit, Third Party Advisory
- https://www.win-rar.com/whatsnew.htmlRelease Notes, Vendor Advisory
- http://www.securityfocus.com/bid/106948Third Party Advisory, VDB Entry
- https://research.checkpoint.com/extracting-code-execution-from-winrar/Exploit, Third Party Advisory
- https://www.win-rar.com/whatsnew.htmlRelease Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20252?
How severe is CVE-2018-20252?
How do I fix CVE-2018-20252?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-20247In Foxit Quick PDF Library (all versions prior to 16.12), is…7.8
- CVE-2018-20248In Foxit Quick PDF Library (all versions prior to 16.12), is…
- CVE-2018-20249In Foxit Quick PDF Library (all versions prior to 16.12), is…
- CVE-2018-2025IBM Spectrum Protect Backup-Archive Client and IBM Spectrum …4.4
- CVE-2018-20250In WinRAR versions prior to and including 5.61, There is pat…7.8
- CVE-2018-20251In WinRAR versions prior to and including 5.61, there is pat…
- CVE-2018-20253In WinRAR versions prior to and including 5.60, There is an …
- CVE-2018-2026IBM Financial Transaction Manager 3.2.1 for Digital Payments…4.3
- CVE-2018-2028IBM Maximo Asset Management 7.6 could allow a an authenticat…6.5
- CVE-2018-20298S3 Browser before 8.1.5 contains an XML external entity (XXE…
- CVE-2018-20299An issue was discovered in several Bosch Smart Home cameras …9.8
- CVE-2018-20300Empire CMS 7.5 allows remote attackers to execute arbitrary …
Are you affected by CVE-2018-20252?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
