← Vulnerability feed

Vulnerability record · CVE-2018-20251 · published 5 February 2019

CVE-2018-20251: Rarlab winrar path traversal vulnerability

Rarlab · Winrar

In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNACEV2.dll) creates files and folders as written in the filename field even when WinRAR validator noticed the traversal attempt and requestd to abort the extraction process. the operation is cancelled only after the folders and files were created but prior to them being written, therefore allowing the attacker to create empty files and folders everywhere in the file system.

5.5 CVSS 3.0 Medium EPSS 32% · top 1.8% CWE-693 · CWE-693CWE-22 · Path traversal
5.5CVSS 3.0 base score, v2 4.3
32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNACEV2.dll) creates files and folders as written in the filename field even when WinRAR validator noticed the traversal attempt and requestd to abort the extraction process. the operation is cancelled only after the folders and files were created but prior to them being written, therefore allowing the attacker to create empty files and folders everywhere in the file system.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-20251 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.4CVE-2025-8088WinRAR path traversal lets crafted archives execute codeCVE-2025-8088 is a path traversal flaw in the Windows version of WinRAR that allows attackers to execute arbitrary code by crafting malicious archive…KEVEPSS 94%analysed7.8CVE-2025-6218WinRAR path traversal in archive file handling leads to code executionWinRAR mishandles file paths inside archive files, allowing a crafted path to traverse out of the intended extraction directory (CWE-22). Because the…KEVEPSS 90%analysed7.8CVE-2023-38831WinRAR ZIP archive spoofing leads to arbitrary code executionWinRAR before 6.23 mishandles ZIP archives that contain a benign file and a folder with the same name, causing the folder's contents to be processed …KEVEPSS 100%analysed7.8CVE-2018-20250WinRAR ACE filename path traversal enables arbitrary file writeWinRAR versions up to and including 5.61 mishandle the filename field in ACE archives processed by UNACEV2.dll, allowing a crafted filename to be tre…KEVEPSS 96%analysed10.0CVE-2008-7144Rarlab winrar vulnerabilityMultiple unspecified vulnerabilities in RARLAB WinRAR before 3.71 have unknown impact and attack vectors related to crafted (1) ACE, (2) ARJ, (3) BZ2…EPSS 2.3%10.0CVE-2004-1254Rarlab winrar vulnerabilityWinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, …EPSS 10%10.0CVE-2004-0234Clearswift mailsweeper memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow…EPSS 10%9.3CVE-2006-3845Rarlab winrar vulnerabilityStack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a …EPSS 7.9%

Source: NIST National Vulnerability Database (record CVE-2018-20251), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.