Back

HIGH KEV Used in ransomware campaigns

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll)

Published Feb 5, 2019 ·Due Aug 15, 2022

Description

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

Affected products

Remediation

No remediation recorded yet.

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner checkpoint
Published Feb 5, 2019
Updated Aug 13, 2026
Reserved Dec 19, 2018

CISA Vulnrichment

Updated Feb 7, 2025

NVD

Status Analyzed
Modified Aug 13, 2026

Red Hat

No data

ENISA EUVD

Assigner checkpoint
Published Feb 5, 2019
Updated Aug 13, 2026
Exploited since Feb 15, 2022

GitHub

No data