CVE-2018-20250
גבוהה 7.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- WinRAR Absolute Path Traversal Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 96% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-36, CWE-22
מוצרים מושפעים
rarlab: winrar
קישורים
- http://packetstormsecurity.com/files/152618/RARLAB-WinRAR-ACE-Format-Input-Val… ExploitThird Party AdvisoryVDB Entry
- https://github.com/blau72/CVE-2018-20250-WinRAR-ACE ExploitThird Party Advisory
- https://research.checkpoint.com/extracting-code-execution-from-winrar/ ExploitPress/Media CoverageThird Party Advisory
- https://www.exploit-db.com/exploits/46552/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46756/ ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/152618/RARLAB-WinRAR-ACE-Format-Input-Val… ExploitThird Party AdvisoryVDB Entry
- https://github.com/blau72/CVE-2018-20250-WinRAR-ACE ExploitThird Party Advisory
- https://research.checkpoint.com/extracting-code-execution-from-winrar/ ExploitPress/Media CoverageThird Party Advisory
- https://www.exploit-db.com/exploits/46552/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46756/ ExploitThird Party AdvisoryVDB Entry