THREATOPS
THREAT OPSThreat News › [NVD] CVE-2018-20250 (HIGH 7.8) — In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating

[NVD] CVE-2018-20250 (HIGH 7.8) — In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating

lownvdPublished 2019-02-05

CVE-2018-20250 CVSS: 7.8 HIGH Published: 2019-02-05T20:29:00.243

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2018-20250