CVE Tools

Description

In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNACEV2.dll) creates files and folders as written in the filename field even when WinRAR validator noticed the traversal attempt and requestd to abort the extraction process. the operation is cancelled only after the folders and files were created but prior to them being written, therefore allowing the attacker to create empty files and folders everywhere in the file system.

In plain language

AI Worth attention

If you use WinRAR (5.61 or older), a specially made ACE archive can cause WinRAR to create empty files and folders in unintended locations while extracting—so you should update to a newer version.

Executive summary

Unauthenticated path traversal in WinRAR’s ACE extraction (UNACEV2.dll) allows crafted “filename” fields to escape intended directories and create filesystem entries before extraction is fully aborted.

If affected, business impact
Unexpected files createdFolder clutter and disruptionOperational disruption during extractionPotential access to planted placeholders

What to do now

  1. Check whether you run WinRAR and what version is installed (look for the WinRAR version number).
  2. If your WinRAR version is 5.61 or older, plan an upgrade now.
  3. Upgrade WinRAR to the fixed version: 5.70 Beta 1.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:LAC:LPR:NUI:RS:UC:NI:HA:N
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:UScope
Unchanged
Impact
C:NConfidentiality
None
I:HIntegrity
High
A:NAvailability
None

Weaknesses

Affected Products

rarlab
commercialaka unrar, winrar, rar

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Collection
Discovery
View detailed technique mapping

References

and 2 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2018-20251 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store