Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to overwrite arbitrary files via the SaveToFile method. NOTE: the victim must explicitly allow the code to run.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.145
EPSS Ranking 94.2%