5
CVE-2002-1139
- EPSS 4.23%
- Veröffentlicht 11.10.2002 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:58:47
- Erkennungen
The Compressed Folders feature in Microsoft Windows 98 with Plus! Pack, Windows Me, and Windows XP does not properly check the destination folder during the decompression of ZIP files, which allows attackers to place an executable file in a known location on a user's system, aka "Incorrect Target Path for Zipped File Decompression."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows Xp Edition home
Microsoft ≫ Windows Xp Update gold Edition professional
Microsoft ≫ Windows Xp Update sp1 Edition home
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.23% | 0.897 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-054
http://www.iss.net/security_center/static/10252.php
http://www.securityfocus.com/bid/5876