# CVE-2018-20250

## Summary

- **CVE ID:** CVE-2018-20250
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- **CWE:** CWE-36
- **Published:** Feb 5, 2019
- **Last Modified:** Aug 13, 2026

## Description

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

## Affected Products

- Check Point Software Technologies Ltd. — WinRAR (All versions prior and including 5.61)

## References

- [CNA](https://github.com/blau72/CVE-2018-20250-WinRAR-ACE)
- [CNA](https://research.checkpoint.com/extracting-code-execution-from-winrar/)
- [CNA](https://www.exploit-db.com/exploits/46552/)
- [CNA](http://www.securityfocus.com/bid/106948)
- [CNA](https://www.win-rar.com/whatsnew.html)
- [CNA](http://packetstormsecurity.com/files/152618/RARLAB-WinRAR-ACE-Format-Input-Validation-Remote-Code-Execution.html)
- [CNA](http://www.rapid7.com/db/modules/exploit/windows/fileformat/winrar_ace)
- [CNA](https://www.exploit-db.com/exploits/46756/)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-20250)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 93.46%
- **EPSS Percentile:** 99.8

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Feb 15, 2022
- **Due Date:** Aug 15, 2022

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._