#VU17819 Out-of-bounds write in WinRAR - CVE-2018-20253
Published: February 21, 2019 / Updated: May 18, 2020
WinRAR
RARLAB
Description
The vulnerability allows a local attacker to gain elevated privileges.
The vulnerability exists due to out-of-bounds write during parsing crafted LHA / LZH archive formats. A local attacker can supply specially crafted input, trigger memory corruption and execute arbitrary code with elevated privileges.