KEV · Actively exploited
CVE-2018-20250
HIGH 7.8
KEV
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.
Attack vector : Local
No privileges required
Show raw CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
96.27%
exploit likely
percentile 99.9%
CISA Known Exploited Vulnerability
- Added to KEV
- 2022-02-15
- Remediation deadline
- 2022-08-15
- Required action
- Apply updates per vendor instructions.
- Ransomware
- Yes, known ransomware campaign
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| rarlab |
winrar All platforms (wildcard)
|
All platforms (wildcard) | ≤5.61 | cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:* |