PT-2002-2138 · Microsoft · Windows+1

Published

2002-10-11

·

Updated

2018-10-12

·

CVE-2002-1139

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft Windows versions prior to the fixed version
Description: The issue arises from the Compressed Folders feature in Microsoft Windows not properly checking the destination folder during the decompression of ZIP files. This allows attackers to place an executable file in a known location on a user's system.
Recommendations: For Microsoft Windows 98 with Plus! Pack, Windows Me, and Windows XP, update to a version that includes the fix for the Compressed Folders feature to properly check the destination folder during ZIP file decompression. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1139

Affected Products

Compressed Folders
Windows