← Vulnerability feed

Vulnerability record · CVE-2018-20250 · published 5 February 2019

CVE-2018-20250: WinRAR ACE filename path traversal enables arbitrary file write

Rarlab · Winrar

WinRAR versions up to and including 5.61 mishandle the filename field in ACE archives processed by UNACEV2.dll, allowing a crafted filename to be treated as an absolute path and ignoring the chosen extraction folder. This lets an attacker write files to arbitrary locations on the victim's system when the archive is extracted.

7.8 CVSS 3.1 High CISA KEV since 15 Feb 2022 Known ransomware use EPSS 96% · top 0.1% CWE-36 · CWE-36CWE-22 · Path traversal
7.8CVSS 3.1 base score, v2 6.8
96%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
17References, 10 tagged exploit
13 Aug 2026Last modified by NVD

Description

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with known ransomware use, has a very high EPSS score, and public exploits exist, making it a high-risk, actively exploited vulnerability.

What it is

WinRAR versions up to and including 5.61 mishandle the filename field in ACE archives processed by UNACEV2.dll, allowing a crafted filename to be treated as an absolute path and ignoring the chosen extraction folder. This lets an attacker write files to arbitrary locations on the victim's system when the archive is extracted.

Impact

An attacker can write files outside the intended extraction directory, which can lead to code execution in the context of the user who extracts the archive. The CVSS vector indicates high confidentiality, integrity, and availability impact.

Attack surface

The flaw is reached locally when a user extracts a malicious ACE archive with WinRAR; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N). No remote network access is needed beyond delivering the archive file.

Exploitation

CISA KEV lists this as known exploited with ransomware campaign use, and EPSS is 0.96274 (99.877th percentile). Multiple public exploit references exist, confirming active exploitation.

What to do

  • Update WinRAR to a version after 5.61 as directed by the vendor.
  • Remove or disable the legacy UNACEV2.dll if it cannot be updated immediately.
  • Block or scan ACE archives at email and web gateways where feasible.
  • Educate users not to extract untrusted ACE archives.
  • Apply the CISA KEV required action per vendor instructions.

Detection

  • Monitor for file creation events in unexpected system directories (e.g., Startup folders) originating from archive extraction processes.
  • Alert on WinRAR or UNACEV2.dll loading ACE files from untrusted sources.
  • Search for known exploit filenames or paths associated with public PoCs.
  • Review endpoint logs for suspicious child processes spawned by WinRAR.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-20250 to the Known Exploited Vulnerabilities catalog on 15 February 2022 as "WinRAR Absolute Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 August 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/152618/RARLAB-WinRAR-ACE-Format-Input-Validation-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://www.rapid7.com/db/modules/exploit/windows/fileformat/winrar_ace Third Party Advisory
http://www.securityfocus.com/bid/106948 Broken LinkThird Party AdvisoryVDB Entry
https://github.com/blau72/CVE-2018-20250-WinRAR-ACE ExploitThird Party Advisory
https://research.checkpoint.com/extracting-code-execution-from-winrar/ ExploitPress/Media CoverageThird Party Advisory
https://www.exploit-db.com/exploits/46552/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/46756/ ExploitThird Party AdvisoryVDB Entry
https://www.win-rar.com/whatsnew.html Release Notes
http://packetstormsecurity.com/files/152618/RARLAB-WinRAR-ACE-Format-Input-Validation-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://www.rapid7.com/db/modules/exploit/windows/fileformat/winrar_ace Third Party Advisory
http://www.securityfocus.com/bid/106948 Broken LinkThird Party AdvisoryVDB Entry
https://github.com/blau72/CVE-2018-20250-WinRAR-ACE ExploitThird Party Advisory
https://research.checkpoint.com/extracting-code-execution-from-winrar/ ExploitPress/Media CoverageThird Party Advisory
https://www.exploit-db.com/exploits/46552/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/46756/ ExploitThird Party AdvisoryVDB Entry
https://www.win-rar.com/whatsnew.html Release Notes
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-20250 US Government Resource

Track CVE-2018-20250 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.4CVE-2025-8088WinRAR path traversal lets crafted archives execute codeCVE-2025-8088 is a path traversal flaw in the Windows version of WinRAR that allows attackers to execute arbitrary code by crafting malicious archive…KEVEPSS 94%analysed7.8CVE-2025-6218WinRAR path traversal in archive file handling leads to code executionWinRAR mishandles file paths inside archive files, allowing a crafted path to traverse out of the intended extraction directory (CWE-22). Because the…KEVEPSS 90%analysed7.8CVE-2023-38831WinRAR ZIP archive spoofing leads to arbitrary code executionWinRAR before 6.23 mishandles ZIP archives that contain a benign file and a folder with the same name, causing the folder's contents to be processed …KEVEPSS 100%analysed10.0CVE-2008-7144Rarlab winrar vulnerabilityMultiple unspecified vulnerabilities in RARLAB WinRAR before 3.71 have unknown impact and attack vectors related to crafted (1) ACE, (2) ARJ, (3) BZ2…EPSS 2.3%10.0CVE-2004-1254Rarlab winrar vulnerabilityWinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, …EPSS 10%10.0CVE-2004-0234Clearswift mailsweeper memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow…EPSS 10%9.3CVE-2006-3845Rarlab winrar vulnerabilityStack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a …EPSS 7.9%7.8CVE-2023-40477Rarlab winrar vulnerabilityRARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to e…EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2018-20250), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.