Threat Monitor

 

« Zurück zur Liste

Troj.Exploit.HTML.CVE-2010-1885.a

 
Aliase:
Pattern:201007231330
Threat Typ Verbreitung Betroffene Systeme Gefährlichkeit
  • Exploit
  • HTTP
  • Windows NT
  • Windows XP
  • Windows 2000
  • Windows 95/98/ME
  • MS-DOS
  • Other
  • Low
 
Description: Microsoft Windows Help And Support Center is prone to a trusted document whitelist bypass vulnerability.
The vulnerability is caused due to an error in the the MPC::HTML::UrlUnescapeW() function that does not properly check the return code of MPC::HexToNum() when processing escaped URLs through Microsoft Windows Help and Support Center (helpctr.exe). By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to bypass the FromHCP restricted whitelist and execute arbitrary commands on the system through the use of an additional input sanitation error in the sysinfomain.htm help document when opening a specially crafted "hcp://" URL.

Affected: Microsoft Windows XP SP3
Microsoft Windows XP SP2
Microsoft Windows Server 2003 SP2

Nach oben

Partner Login

Mit dem PowerShift Programm haben Sie viele Ressourcen immer zur Hand.

Login Seite:
Loggen Sie sich hier ein

Registrierung als Powershift-Fachhandels-Partner:
Zum Antragsformular

Passwort vergessen:
Neues Password anfordern