Vulnerability record · CVE-2018-20251 · published 5 February 2019
CVE-2018-20251: Rarlab winrar path traversal vulnerability
Rarlab · Winrar
In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNACEV2.dll) creates files and folders as written in the filename field even when WinRAR validator noticed the traversal attempt and requestd to abort the extraction process. the operation is cancelled only after the folders and files were created but prior to them being written, therefore allowing the attacker to create empty files and folders everywhere in the file system.
Description
In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNACEV2.dll) creates files and folders as written in the filename field even when WinRAR validator noticed the traversal attempt and requestd to abort the extraction process. the operation is cancelled only after the folders and files were created but prior to them being written, therefore allowing the attacker to create empty files and folders everywhere in the file system.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/106948 | Third Party AdvisoryVDB Entry |
| https://research.checkpoint.com/extracting-code-execution-from-winrar/ | ExploitThird Party Advisory |
| https://www.win-rar.com/whatsnew.html | Release NotesVendor Advisory |
| http://www.securityfocus.com/bid/106948 | Third Party AdvisoryVDB Entry |
| https://research.checkpoint.com/extracting-code-execution-from-winrar/ | ExploitThird Party Advisory |
| https://www.win-rar.com/whatsnew.html | Release NotesVendor Advisory |
Track CVE-2018-20251 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-20251), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.