Vulnerability Description
In WinRAR versions prior to and including 5.60, There is an out-of-bounds write vulnerability during parsing of a crafted LHA / LZH archive formats. Successful exploitation could lead to arbitrary code execution in the context of the current user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rarlab | Winrar | <= 5.60 |
Related Weaknesses (CWE)
References
- https://research.checkpoint.com/extracting-code-execution-from-winrar/ExploitThird Party Advisory
- https://www.win-rar.com/whatsnew.htmlRelease NotesVendor Advisory
- https://research.checkpoint.com/extracting-code-execution-from-winrar/ExploitThird Party Advisory
- https://www.win-rar.com/whatsnew.htmlRelease NotesVendor Advisory
FAQ
What is CVE-2018-20253?
CVE-2018-20253 is a vulnerability with a CVSS score of 7.8 (HIGH). In WinRAR versions prior to and including 5.60, There is an out-of-bounds write vulnerability during parsing of a crafted LHA / LZH archive formats. Successful exploitation could lead to arbitrary cod...
How severe is CVE-2018-20253?
CVE-2018-20253 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20253?
Check the references section above for vendor advisories and patch information. Affected products include: Rarlab Winrar.