Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:47
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=108437759930820&w=2 - | |
References | () http://marc.info/?l=full-disclosure&m=108430407801825&w=2 - | |
References | () http://www.exploitlabs.com/files/advisories/EXPL-A-2004-001-helpctr.txt - | |
References | () http://www.kb.cert.org/vuls/id/484814 - Patch, Third Party Advisory, US Government Resource | |
References | () http://www.securityfocus.com/bid/10321 - Exploit, Patch, Vendor Advisory | |
References | () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-015 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/16095 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1008 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1032 - |
Information
Published : 2004-06-14 04:00
Updated : 2024-11-20 23:47
NVD link : CVE-2004-0199
Mitre link : CVE-2004-0199
CVE.ORG link : CVE-2004-0199
JSON object : View
Products Affected
microsoft
- windows_xp
- windows_2003_server
CWE