CVE-2018-20251
In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 31.5%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNACEV2.dll) creates files and folders as written in the filename field even when WinRAR validator noticed the traversal attempt and requestd to abort the extraction process. the operation is cancelled only after the folders and files were created but prior to them being written, therefore allowing the attacker to create empty files and folders everywhere in the file system.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 31.53% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-693, CWE-22
- Affected
- rarlab/winrar
- Source
- cve@checkpoint.com
References
- http://www.securityfocus.com/bid/106948Third Party Advisory, VDB Entry
- https://research.checkpoint.com/extracting-code-execution-from-winrar/Exploit, Third Party Advisory
- https://www.win-rar.com/whatsnew.htmlRelease Notes, Vendor Advisory
- http://www.securityfocus.com/bid/106948Third Party Advisory, VDB Entry
- https://research.checkpoint.com/extracting-code-execution-from-winrar/Exploit, Third Party Advisory
- https://www.win-rar.com/whatsnew.htmlRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.