CVE-2018-20250 — WinRAR Absolute Path Traversal Vulnerability
2022-02-15 • CISA Known Exploited Vulnerability
[event] WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution
> AFFECTED SOFTWARE
| Field | Value |
|---|---|
| Vendor | RARLAB |
| Product | WinRAR |
| CWE | CWE-36 |
| CVE ID | CVE-2018-20250 |
| Date Added | 2022-02-15 |
| Due Date | 2022-08-15 |
| Ransomware Campaign | Known — this vulnerability has been leveraged in ransomware campaigns |
> MITIGATION
Apply updates per vendor instructions.
Due Date: 2022-08-15