CVE-2018-20250
Summary
| CVE | CVE-2018-20250 |
|---|---|
| State | PUBLISHED |
| Assigner | checkpoint |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-02-05 20:29:00 UTC |
| Updated | 2026-08-13 05:17:17 UTC |
| Description | In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.962740000 probability, percentile 0.998740000 (date 2026-08-27)
CISA KEV: Listed on 2022-02-15; due 2022-08-15; ransomware use Known
Problem Types: CWE-36 | CWE-22 | CWE-36 CWE-36: Absolute Path Traversal
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
CISA Known Exploited Vulnerability
| Vendor | RARLAB |
|---|---|
| Product | WinRAR |
| Name | WinRAR Absolute Path Traversal Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2018-20250 |
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Check Point Software Technologies Ltd. | WinRAR | affected All versions prior and including 5.61 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| WinRAR download and support: Whats New | af854a3a-2127-422b-91ae-364da2661108 | www.win-rar.com | Release Notes |
| WinRAR 5.61 - Path Traversal | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| RARLAB WinRAR ACE Format Input Validation Remote Code Execution ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| RARLAB WinRAR ACE Format Input Validation Remote Code Execution | af854a3a-2127-422b-91ae-364da2661108 | www.rapid7.com | Third Party Advisory |
| WinRAR Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| Extracting a 19 Year Old Code Execution from WinRAR - Check Point Research | af854a3a-2127-422b-91ae-364da2661108 | research.checkpoint.com | Exploit, Press/Media Coverage, Third Party Advisory |
| GitHub - blau72/CVE-2018-20250-WinRAR-ACE: Proof of concept code in C# to exploit the WinRAR ACE file extraction path (CVE-2018-20250). | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Third Party Advisory |
| RARLAB WinRAR 5.61 - ACE Format Input Validation Remote Code Execution (Metasploit) - Windows local Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2022-02-15T00:00:00.000Z | CVE-2018-20250 added to CISA KEV |
There are currently no legacy QID mappings associated with this CVE.