CVE-2018-20253: High severity winrar vulnerability
Published Feb 13, 2019
·Updated
In WinRAR versions prior to and including 5.60, There is an out-of-bounds write vulnerability during parsing of a crafted LHA / LZH archive formats. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Affected Software
1 affected component
RARLAB WinRAR<=5.60
Event History
Feb 13, 2019
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-20253?
CVE-2018-20253 is an out-of-bounds write vulnerability in WinRAR versions prior to and including 5.60.
2
What is the severity of CVE-2018-20253?
CVE-2018-20253 has a severity rating of 7.8, which is considered high.
3
What software is affected by CVE-2018-20253?
CVE-2018-20253 affects WinRAR versions up to and including 5.60.
4
How does CVE-2018-20253 allow arbitrary code execution?
CVE-2018-20253 allows arbitrary code execution by exploiting an out-of-bounds write vulnerability in the parsing of crafted LHA / LZH archive formats.
5
How can I fix CVE-2018-20253?
To fix CVE-2018-20253, update WinRAR to version 5.61 or later, which contains a patch for the vulnerability.