|
Microsoft Compressed Folders Hostile Decompression Path Vulnerability
The Compressed Folders feature allows zipped archives to be treated as folders. The vulnerability is the result of a flaw in the decompression routine. This results in an attacker being able to specify a hostile path for files when a zipped archive is decompressed. This will allow an attacker to decompress files and store the files in an attacker-specified directory on the filesystem. |
|
|
Privacy Statement |