SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2018-20250

WinRAR Absolute Path Traversal Vulnerability

KEVHIGH 7.8EPSS 96.3%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 August 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
96.27% probability · 100th percentile
CISA KEV
Listed 15 February 2022 · due 15 August 2022 · used in ransomware campaigns
Weakness
CWE-36, CWE-22
Affected
rarlab/winrar
Source
cve@checkpoint.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-20250

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.