CWE-69: Improper Handling of Windows ::DATA Alternate Data Stream

VariantIncomplete

The product does not properly prevent access to, or detect usage of, alternate data streams (ADS).

View on MITRE
Back to CWE Lookup

Extended Description

An attacker can use an ADS to hide information about a file (e.g. size, the name of the process) from a system or file browser tools such as Windows Explorer and 'dir' at the command line utility. Alternately, the attacker might be able to bypass intended access restrictions for the associated data fork.

Technical Details

Structure
Simple

Applicable To

Languages
Not Language-Specific
Platforms
Windows

Learn More