← Back to CVE List
Vulnerability Intelligence Report
WinRAR Absolute Path Traversal Vulnerability

CVE-2018-20250

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:96.27%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-36 ↗CWE-36: Absolute Path Traversal

Affected Products & Versions

Vendor Product Affected Versions
Check Point Software Technologies Ltd. WinRAR All versions prior and including 5.61 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
96.274%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCheck Point Software Ltd. · Vendor · Israel
Reserved2018-12-19T00:00:00
Published2019-02-05T20:00:00
Patch Date2019-02-05
Last Updated2026-08-13T03:55:27

LINK COPIED TO CLIPBOARD