ID:2715 - Exploit for Out-of-bounds write in WinRAR - CVE-2018-20253

 
Main Vulnerability Database Exploits ID:2715 - Exploit for Out-of-bounds write in WinRAR - CVE-2018-20253

ID:2715 - Exploit for Out-of-bounds write in WinRAR - CVE-2018-20253

Published: May 18, 2020


Vulnerability identifier: #VU17819
Vulnerability risk: Low
CVE-ID: CVE-2018-20253
CWE-ID: CWE-787
Exploitation vector: Local access
Vulnerable software:
WinRAR

Link to public exploit:


Vulnerability description

The vulnerability allows a local attacker to gain elevated privileges.

The vulnerability exists due to out-of-bounds write during parsing crafted LHA / LZH archive formats. A local attacker can supply specially crafted input, trigger memory corruption and execute arbitrary code with elevated privileges.


Remediation

Update to version 5.70 Beta 1.