#VU17470 Out-of-bounds write in WinRAR - CVE-2018-20252
Published: February 11, 2019 / Updated: May 18, 2020
WinRAR
RARLAB
Description
The vulnerability allows a local attacker to gain elevated privileges.
The vulnerability exists due to out-of-bounds write during parsing of crafted ACE and RAR archive formats. A local attacker can supply specially crafted input, trigger memory corruption and execute arbitrary code with elevated privileges.