CVE-2002-1139

Microsoft Windows 98 with Plus! Pack/Me/XP - Path Traversal

Title source: llm
STIX 2.1

Description

The Compressed Folders feature in Microsoft Windows 98 with Plus! Pack, Windows Me, and Windows XP does not properly check the destination folder during the decompression of ZIP files, which allows attackers to place an executable file in a known location on a user's system, aka "Incorrect Target Path for Zipped File Decompression."

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5876
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10252.php

Scores

EPSS 0.0423
EPSS Percentile 90.1%

Details

Status published
Products (3)
microsoft/windows_98_plus_pack
microsoft/windows_me
microsoft/windows_xp (3 CPE variants)
Published Oct 11, 2002
Tracked Since Feb 18, 2026