| Vulnerability Name: | CVE-2002-1139 (CCN-10252) | ||||||||
| Assigned: | 2002-10-02 | ||||||||
| Published: | 2002-10-02 | ||||||||
| Updated: | 2018-10-12 | ||||||||
| Summary: | The Compressed Folders feature in Microsoft Windows 98 with Plus! Pack, Windows Me, and Windows XP does not properly check the destination folder during the decompression of ZIP files, which allows attackers to place an executable file in a known location on a user's system, aka "Incorrect Target Path for Zipped File Decompression." | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2002-1139 Source: CCN Type: CIAC Information Bulletin N-001 Microsoft File Decompression Functions Vulnerabilities Source: XF Type: Vendor Advisory win-zip-incorrect-path(10252) Source: CCN Type: Microsoft Security Bulletin MS02-054 Unchecked Buffer in File Decompression Functions Could Lead to Code Execution (Q329048) Source: CCN Type: Microsoft Security Bulletin MS04-034 Vulnerability in Compressed (zipped) Folders Could Allow Remote Code Execution (873376) Source: CCN Type: OSVDB ID: 868 Microsoft Windows Compressed Folders ZIP Decompression Arbitrary File Write Source: BID Type: UNKNOWN 5876 Source: CCN Type: BID-5876 Microsoft Compressed Folders Hostile Decompression Path Vulnerability Source: MS Type: UNKNOWN MS02-054 Source: XF Type: UNKNOWN win-zip-incorrect-path(10252) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||