CVE-2009-2544

medium Microsoft
CVSS v3 Base Score
6.8
AV:N/AC:L/Au:S/C:C/I:N/A:N
EPSS Score
2.2%
Exploitation probability in 30 days
Top 15% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
C
Integrity
None
Availability
None
Published: July 20, 2009 (6142 days ago)
Last Modified: April 23, 2026
Vendor: Microsoft
Source: NVD

Description

Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! Live (MPL) allows remote authenticated users to list arbitrary directories and read arbitrary files via a .. (dot dot) in a pathname.

CWE

CWE-22

Affected Products

marcelo costa fileserver

References