Back

CVE-2009-0244

HIGH

Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list arbitrary directories, and create or read arbitrary files, via a .. (dot dot) in a pathname. NOTE: this can be leveraged for code execution by writing to a Startup folder.

Published: Jan 21, 2009 Modified: Apr 23, 2026
CWE-22

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: LOW User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products (6)

Vendor Product Version
microsoft windows_mobile 5.0
microsoft windows_mobile 5.0
microsoft windows_mobile 5.0
microsoft windows_mobile 6.0
microsoft windows_mobile 6.0
microsoft windows_mobile 6.0

GitHub Security Advisory GHSA-6gmh-pw6w-cww4

Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in...

Risk Scores

CVSS Score 8.8 / 10
EPSS Score 17.36%

Top 5% most likely to be exploited

Threat Score 40.4 / 100

Data Sources

NVD EPSS GitHub