KEV · Activement exploitée
CVE-2018-20250
HIGH 7.8
KEV
EN In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.
Vecteur d'attaque : Local
Aucun privilège requis
Voir le vecteur CVSS brut
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
96.27%
exploit probable
percentile 99.9%
CISA Known Exploited Vulnerability
- Ajouté au KEV
- 2022-02-15
- Deadline remédiation
- 2022-08-15
- Action requise
- Apply updates per vendor instructions.
- Ransomware
- Oui, campagne ransomware connue
Apps suivies liées à cette CVE
Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.
Configurations CPE vulnérables (1)
| Vendor | Produit | Plateforme | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| rarlab |
winrar Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | ≤5.61 | cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:* |