A AegiFlow
HIGHCVSS 7.8KNOWN EXPLOITEDRANSOMWARE: KNOWN

CVE-2018-20250

CVE-2018-20250 updated by NVD

Published
2022-02-15
Modified
2026-09-21
Sources
cisa-kev, nvd

Summary

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.