CVE-2002-1139
Pack, Windows Me, and Windows XP does not properly check the destination folder during the decompression of ZIP files, which allows attackers to place an executable file in a known location on a user's system, aka "Incorrect Target Path for Zipped File…
Does this matter?
Lower severity and a low EPSS score (4.23%). Track it; it rarely justifies an emergency change on its own.
Description
The Compressed Folders feature in Microsoft Windows 98 with Plus! Pack, Windows Me, and Windows XP does not properly check the destination folder during the decompression of ZIP files, which allows attackers to place an executable file in a known location on a user's system, aka "Incorrect Target Path for Zipped File Decompression."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 4.23% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 98 plus pack · microsoft/windows me · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://www.iss.net/security_center/static/10252.phpVendor Advisory
- http://www.securityfocus.com/bid/5876
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-054
- http://www.iss.net/security_center/static/10252.phpVendor Advisory
- http://www.securityfocus.com/bid/5876
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-054
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.