CVE-2009-2544 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 3.4% (pctl 89)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! Live (MPL) allows remote authenticated users to list arbitrary directories and read arbitrary files via a .. (dot dot) in a pathname.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
| EPSS | 3.43% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-07-20 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| marcelo costa | fileserver |
| microsoft | messenger plus\! live |
| microsoft | windows live messenger |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Windows Live Messenger Plus! Fileserver 1.0 - Directory Traversal | 2009-07-09 |
→ the Explorer · watch your stack · NVD