CVE-2009-0244: Path Traversal

Published Jan 21, 2009
·
Updated

Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list arbitrary directories, and create or read arbitrary files, via a .. (dot dot) in a pathname. NOTE: this can be leveraged for code execution by writing to a Startup folder.

Affected Software

6 affected components
Microsoft Windows Mobile=6.0
Microsoft Windows Mobile=6.0
Microsoft Windows Mobile=5.0
Microsoft Windows Mobile=5.0
Microsoft Windows Mobile=6.0
Microsoft Windows Mobile=5.0

Event History

Jan 21, 2009
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:30 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2009-0244?

CVE-2009-0244 has a moderate severity rating as it allows remote authenticated users to exploit the directory traversal vulnerability in the OBEX FTP Service.

2

How do I fix CVE-2009-0244?

To fix CVE-2009-0244, update your Microsoft Windows Mobile device to the latest firmware version that addresses this vulnerability.

3

Which versions of Windows Mobile are affected by CVE-2009-0244?

CVE-2009-0244 affects Windows Mobile 5.0 and 6.0 devices, including versions for Professional, Standard, and Pocket PC.

4

What kind of access can an attacker gain through CVE-2009-0244?

An attacker can gain the ability to list arbitrary directories, and create or read arbitrary files on vulnerable devices through CVE-2009-0244.

5

Who can exploit CVE-2009-0244?

CVE-2009-0244 can be exploited by remote authenticated users who have access to the OBEX FTP Service on the affected Windows Mobile devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203