Description
In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNACEV2.dll) creates files and folders as written in the filename field even when WinRAR validator noticed the traversal attempt and requestd to abort the extraction process. the operation is cancelled only after the folders and files were created but prior to them being written, therefore allowing the attacker to create empty files and folders everywhere in the file system.
In plain language
AI Worth attentionIf you use WinRAR (5.61 or older), a specially made ACE archive can cause WinRAR to create empty files and folders in unintended locations while extracting—so you should update to a newer version.
Unauthenticated path traversal in WinRAR’s ACE extraction (UNACEV2.dll) allows crafted “filename” fields to escape intended directories and create filesystem entries before extraction is fully aborted.
What to do now
- Check whether you run WinRAR and what version is installed (look for the WinRAR version number).
- If your WinRAR version is 5.61 or older, plan an upgrade now.
- Upgrade WinRAR to the fixed version: 5.70 Beta 1.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:NConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-20251 and every CVE in our database. Create a free account — no credit card required.
Create Free Account