CVE-2018-20251 is a path traversal vulnerability affecting WinRAR versions up to and including 5.61, specifically within its UNACE module. This flaw allows an attacker to create empty files and folders anywhere on the file system by crafting a malicious ACE archive, even if WinRAR attempts to abort the extraction. Rated 5.5 (Medium) on CVSS, it requires user interaction (UI:R) and local access (AV:L), with a high impact on integrity (I:H) due to unauthorized file creation. While no active exploits, Metasploit modules, or ExploitDB entries are publicly available, the vulnerability has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.61CPE matchmatch criteria | cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.