Skip to main content

CVE-2018-20250

7.8
HIGHCVSS v3.1 Base Score
93.46%
HIGH RiskEPSS (100th percentile)
KEV

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

Published: 2/5/2019
Modified: 10/31/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

WinRAR Absolute Path Traversal Vulnerability

Vendor / Product:

RARLAB WinRAR

Required Action:

Apply updates per vendor instructions.

Due Date: 8/15/2022(OVERDUE)
Ransomware Campaign Use
Added to KEV:

2/15/2022

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2018-20250

Vulnerability Summary

CVSS v3 Score

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2 Score

6.8

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

93.46%HIGH Exploitation Risk
100th percentile

This vulnerability has a 93.46% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-36)

Similar SeverityHIGH