VYPR
High severity7.8CISA KEVNVD Advisory· Published Feb 5, 2019· Updated Aug 13, 2026

CVE-2018-20250

CVE-2018-20250

Description

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Rarlab/Winrar2 versions
    cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:*range: <=5.61
    • (no CPE)range: <=5.61
  • WinRAR/WinRARllm-fuzzy
    Range: <=5.61
  • Check Point Software Technologies Ltd./WinRARv5
    Range: All versions prior and including 5.61

Patches

Vulnerability mechanics

References

8

News mentions

1