CVE-2001-0152 describes a vulnerability in Microsoft Plus! for Windows 98 and Me, where the password protection for Compressed Folders insecurely stores password information in a file. This allows local attackers to easily recover passwords and access the compressed data. The vulnerability has a low CVSS score of 2.1, indicating a low severity due to requiring local access and only impacting confidentiality. While there are no known active exploits or widespread media coverage, a Metasploit module exists for password extraction, suggesting some level of exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:plus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.