← Back to browse · API

CVE-2018-20250

Severity
HIGH
CVSS
7.8
EPSS
0.96274
Risk score
58.7
CISA KEV
Yes
PoC
No
Published
2019-02-05
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2018-12813, GHSA-7V9Q-J964-43QC
Products
RARLAB:WinRAR, Win-Rar:WinRAR All versions prior and including 5.61
Sources
cisa.gov CVE-2018-20250
euvd EUVD-2018-12813

Description

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

References