SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-1139

Pack, Windows Me, and Windows XP does not properly check the destination folder during the decompression of ZIP files, which allows attackers to place an executable file in a known location on a user's system, aka "Incorrect Target Path for Zipped File…

MEDIUM 5.0EPSS 4.23%

Does this matter?

Lower severity and a low EPSS score (4.23%). Track it; it rarely justifies an emergency change on its own.

Description

The Compressed Folders feature in Microsoft Windows 98 with Plus! Pack, Windows Me, and Windows XP does not properly check the destination folder during the decompression of ZIP files, which allows attackers to place an executable file in a known location on a user's system, aka "Incorrect Target Path for Zipped File Decompression."

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
4.23% probability · 90th percentile
CISA KEV
Not listed
Affected
microsoft/windows 98 plus pack · microsoft/windows me · microsoft/windows xp
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.