First published: Wed Feb 13 2019(Updated: )
In WinRAR versions prior to and including 5.60, There is an out-of-bounds write vulnerability during parsing of a crafted LHA / LZH archive formats. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Credit: cve@checkpoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
WinRAR | <=5.60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20253 is an out-of-bounds write vulnerability in WinRAR versions prior to and including 5.60.
CVE-2018-20253 has a severity rating of 7.8, which is considered high.
CVE-2018-20253 affects WinRAR versions up to and including 5.60.
CVE-2018-20253 allows arbitrary code execution by exploiting an out-of-bounds write vulnerability in the parsing of crafted LHA / LZH archive formats.
To fix CVE-2018-20253, update WinRAR to version 5.61 or later, which contains a patch for the vulnerability.