PT-2019-1468 · Winrar · Winrar

CVE-2018-20250

·

Publicado

2019-02-05

·

Atualizado

2026-08-13

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WinRAR versions prior to and including 5.61
Description The issue is related to a path traversal vulnerability in the unacev2.dll library of WinRAR, which occurs when the filename field of the ACE format is crafted in a specific way. This allows an attacker to ignore the destination folder and treat the filename as an absolute path, enabling them to extract files to arbitrary locations on the disk. The vulnerability can be exploited by manipulating the filename field with specific patterns, effectively allowing code execution. There have been reports of targeted attacks exploiting this vulnerability.
Recommendations For WinRAR versions prior to and including 5.61, update to a version later than 5.61 to resolve the issue. As a temporary workaround, consider avoiding the use of ACE archives or restricting the extraction of files from ACE archives to a safe location until a patch is applied. Additionally, be cautious when extracting files from archives, especially those from untrusted sources, to minimize the risk of exploitation.

Exploit

Correção

RCE

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00860
CVE-2018-20250

Produtos afetados

Winrar