Arbitrary Code Execution Vulnerability in Windows 2003 and Windows XP

new vulnerability in Windows 2003 and XP could result in the execution of arbitrary code on the vulnerable system.

Ken Pfeil

May 12, 2004

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported May 11, 2004, byMicrosoft

VERSIONS AFFECTED

DESCRIPTION
A new vulnerability in Windows 2003 and XP could result in the execution ofarbitrary code on the vulnerable system. This vulnerability is a result of theway that the Help and Support Center service handles Help Center Protocol (HCP)URL validation. A potential attacker could exploit the vulnerability byconstructing a malicious HCP URL that could potentially allow remote codeexecution if a user visited a malicious Web site or viewed a malicious emailmessage.

VENDOR RESPONSE
Microsoft has released bulletinMS04-015, "Vulnerability in Help and Support CenterCould Allow Remote Code Execution" (840374), to address this vulnerabilityand recommends that affected users immediately apply the appropriate patchlisted in the bulletin.

CREDIT
Discovered by Microsoft.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like