ID:2714 - Exploit for Out-of-bounds write in WinRAR - CVE-2018-20252

 
Main Vulnerability Database Exploits ID:2714 - Exploit for Out-of-bounds write in WinRAR - CVE-2018-20252

ID:2714 - Exploit for Out-of-bounds write in WinRAR - CVE-2018-20252

Published: May 18, 2020


Vulnerability identifier: #VU17470
Vulnerability risk: Low
CVE-ID: CVE-2018-20252
CWE-ID: CWE-787
Exploitation vector: Local access
Vulnerable software:
WinRAR

Link to public exploit:


Vulnerability description

The vulnerability allows a local attacker to gain elevated privileges.

The vulnerability exists due to out-of-bounds write during parsing of crafted ACE and RAR archive formats. A local attacker can supply specially crafted input, trigger memory corruption and execute arbitrary code with elevated privileges.


Remediation

Update to version 5.70 Beta 1.