CVE-2018-20250General(rarlab / winrar)

LOWCVSS 7.8 · HIGHCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-08-15. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-36CWE-22

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • winrar

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
winrar

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-01-30: 1Technical Details · 2026-01-30: 101-30
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • たあぬほ)ふじ、 Kestrel@KestrelYTReal
    General

    @ramdileo @NotNordgaren Brother, you're vulnerable not just to the one above but also CVE-2023-38831 File Spoofing CVE-2018-20250 Ace PT CVE-2006-3845 Buffer Overflow All well-known exploits. Old does not equal exploit-free. almost always the opposite, see any legacy Windows version as a example

    Post summary

    The tweet mentions several legacy Windows CVEs, highlighting that older systems remain vulnerable; it provides minimal technical detail and no evidence of active exploitation or patches.

    10000140
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprarlabwinrar---

Explore more