CVE-2009-0244
Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 30.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list arbitrary directories, and create or read arbitrary files, via a .. (dot dot) in a pathname. NOTE: this can be leveraged for code execution by writing to a Startup folder.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 30.25% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- microsoft/windows mobile
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/33598Broken Link
- http://securityreason.com/securityalert/4938Exploit
- http://www.securityfocus.com/archive/1/500199/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/33359Broken Link, Third Party Advisory, VDB Entry
- http://www.seguridadmobile.com/windows-mobile/windows-mobile-security/Microsoft-Bluetooth-Stack-Directory-Traversal.htmlBroken Link, Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48124Third Party Advisory, VDB Entry
- http://secunia.com/advisories/33598Broken Link
- http://securityreason.com/securityalert/4938Exploit
- http://www.securityfocus.com/archive/1/500199/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/33359Broken Link, Third Party Advisory, VDB Entry
- http://www.seguridadmobile.com/windows-mobile/windows-mobile-security/Microsoft-Bluetooth-Stack-Directory-Traversal.htmlBroken Link, Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48124Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.