CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2018-20250

KEV · ransomware High · CVSS 7.8
CVSS
7.8
nvd
EPSS
KEV
Listed
ransomware
Class
other
CWE-36, CWE-22

Description

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

References

Status: profiled · ingested 2026-08-13T06:00:50.000Z