CVE-2018-20253
Last modified
CVE-2018-20253 is a vulnerability of currently unknown severity. In WinRAR versions prior to and including 5.60, There is an out-of-bounds write vulnerability during parsing of a crafted LHA / LZH archive formats. Successful exploitation could lead to arbitrary code execution in the context of the current user.. EPSS estimates a 4.04% chance of exploitation in the next 30 days.
Description
In WinRAR versions prior to and including 5.60, There is an out-of-bounds write vulnerability during parsing of a crafted LHA / LZH archive formats. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rarlab | Winrar | <= 5.60 |
References
- https://research.checkpoint.com/extracting-code-execution-from-winrar/Exploit, Third Party Advisory
- https://www.win-rar.com/whatsnew.htmlRelease Notes, Vendor Advisory
- https://research.checkpoint.com/extracting-code-execution-from-winrar/Exploit, Third Party Advisory
- https://www.win-rar.com/whatsnew.htmlRelease Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20253?
How severe is CVE-2018-20253?
How do I fix CVE-2018-20253?
Are you affected by CVE-2018-20253?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
