VulnerabilityAnalyzed
CVE-2018-20250
WinRAR Absolute Path Traversal Vulnerability
KEVHIGH 7.8EPSS 96.3%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 August 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 96.27% probability · 100th percentile
- CISA KEV
- Listed 15 February 2022 · due 15 August 2022 · used in ransomware campaigns
- Weakness
- CWE-36, CWE-22
- Affected
- rarlab/winrar
- Source
- cve@checkpoint.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-20250
References
- http://packetstormsecurity.com/files/152618/RARLAB-WinRAR-ACE-Format-Input-Validation-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.rapid7.com/db/modules/exploit/windows/fileformat/winrar_aceThird Party Advisory
- http://www.securityfocus.com/bid/106948Broken Link, Third Party Advisory, VDB Entry
- https://github.com/blau72/CVE-2018-20250-WinRAR-ACEExploit, Third Party Advisory
- https://research.checkpoint.com/extracting-code-execution-from-winrar/Exploit, Press/Media Coverage, Third Party Advisory
- https://www.exploit-db.com/exploits/46552/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/46756/Exploit, Third Party Advisory, VDB Entry
- https://www.win-rar.com/whatsnew.htmlRelease Notes
- http://packetstormsecurity.com/files/152618/RARLAB-WinRAR-ACE-Format-Input-Validation-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.rapid7.com/db/modules/exploit/windows/fileformat/winrar_aceThird Party Advisory
- http://www.securityfocus.com/bid/106948Broken Link, Third Party Advisory, VDB Entry
- https://github.com/blau72/CVE-2018-20250-WinRAR-ACEExploit, Third Party Advisory
- https://research.checkpoint.com/extracting-code-execution-from-winrar/Exploit, Press/Media Coverage, Third Party Advisory
- https://www.exploit-db.com/exploits/46552/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/46756/Exploit, Third Party Advisory, VDB Entry
- https://www.win-rar.com/whatsnew.htmlRelease Notes
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-20250US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.