CVE-2009-0244: Path Traversal
Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list arbitrary directories, and create or read arbitrary files, via a .. (dot dot) in a pathname. NOTE: this can be leveraged for code execution by writing to a Startup folder.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0244?
CVE-2009-0244 has a moderate severity rating as it allows remote authenticated users to exploit the directory traversal vulnerability in the OBEX FTP Service.
How do I fix CVE-2009-0244?
To fix CVE-2009-0244, update your Microsoft Windows Mobile device to the latest firmware version that addresses this vulnerability.
Which versions of Windows Mobile are affected by CVE-2009-0244?
CVE-2009-0244 affects Windows Mobile 5.0 and 6.0 devices, including versions for Professional, Standard, and Pocket PC.
What kind of access can an attacker gain through CVE-2009-0244?
An attacker can gain the ability to list arbitrary directories, and create or read arbitrary files on vulnerable devices through CVE-2009-0244.
Who can exploit CVE-2009-0244?
CVE-2009-0244 can be exploited by remote authenticated users who have access to the OBEX FTP Service on the affected Windows Mobile devices.