CVE-2018-20250: WinRAR Absolute Path Traversal Vulnerability
High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2022-02-15. EPSS: 96% chance of exploitation in the next 30 days.
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.
Affected products
- RARLAB WinRAR: up to and including 5.61
Published 2019-02-05. Last modified 2026-08-13.