CVE-2018-20251 - CVE House
Back to Database
Status published Medium CVE-2018-20251

In WinRAR versions prior to and including 5.61, there is...

Vulnerability Description

In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNACEV2.dll) creates files and folders as written in the filename field even when WinRAR validator noticed the traversal attempt and requestd to abort the extraction process. the operation is cancelled only after the folders and files were created but prior to them being written, therefore allowing the attacker to create empty files and folders everywhere in the file system.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-20251

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Check Point Software Technologies Ltd.

View all reports →

Affected Software

WinRAR
Vulnerable Versions:
All versions prior and including 5.61

Timeline

Official Publish: February 5th, 2019
Last Modified: September 16th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Weaknesses (CWE)