February 15, 2022 · Applied Cybernetics Group
CVE-2018-20250 — RARLAB WinRAR
known ransomware use
WinRAR Absolute Path Traversal Vulnerability
- Added to KEV
2022-02-15- Federal due date
2022-08-15- Vendor
- RARLAB
- Product
- WinRAR
- EPSS
- 99.9th percentile (score 0.963, as of
2026-09-16) - NVD CVSS v3.1
- 7.8 (HIGH)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2018-20250
CISA short description
WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution
Required action
Apply updates per vendor instructions.
NVD description
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.