THREAT OPS › Threat News › [NVD] CVE-2018-20250 (HIGH 7.8) — In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating
[NVD] CVE-2018-20250 (HIGH 7.8) — In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating
CVE-2018-20250 CVSS: 7.8 HIGH Published: 2019-02-05T20:29:00.243
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.
Indicators of compromise
- CVE-2018-20250cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2018-20250