KEV · Actively exploited
CVE-2018-20250
CVE-2018-20250 is actively exploited (CISA KEV catalog) : high severity (CVSS 7.8), 1 tracked app concerned, none still exposed on their current version.
- Severity (CVSS)
- 7.8
- Exploitation
- Confirmed
- Tracked apps
- 1
- Still exposed
- 0
NVD scale
CISA KEV · EPSS predicts 96.0 %
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.
Show raw CVSS vector
CISA Known Exploited Vulnerability
- Added to KEV
- 2022-02-15
- Remediation deadline
- 2022-08-15
- Required action
- Apply updates per vendor instructions.
- Ransomware
- Yes, known ransomware campaign
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| rarlab |
winrar All platforms (wildcard)
|
All platforms (wildcard) | ≤5.61 | cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:* |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.