Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2010-1885
Description:The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist (fromHCP option) and execute arbitrary commands via a crafted hcp:// URL, aka "Help Center URL Validation Vulnerability."
Test IDs: 1.3.6.1.4.1.25623.1.0.902080  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2010-1885
BugTraq ID: 40725
http://www.securityfocus.com/bid/40725
Bugtraq: 20100609 Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly (Google Search)
http://www.securityfocus.com/archive/1/511774/100/0/threaded
Bugtraq: 20100610 Re: Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly (Google Search)
http://www.securityfocus.com/archive/1/511783/100/0/threaded
Cert/CC Advisory: TA10-194A
http://www.us-cert.gov/cas/techalerts/TA10-194A.html
CERT/CC vulnerability note: VU#578319
http://www.kb.cert.org/vuls/id/578319
http://www.exploit-db.com/exploits/13808
http://archives.neohapsis.com/archives/fulldisclosure/2010-06/0197.html
http://blogs.technet.com/b/msrc/archive/2010/06/10/windows-help-vulnerability-disclosure.aspx
Microsoft Security Bulletin: MS10-042
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-042
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11733
http://www.securitytracker.com/id?1024084
http://secunia.com/advisories/40076
http://www.vupen.com/english/advisories/2010/1417
XForce ISS Database: ms-win-helpctr-command-execution(59267)
https://exchange.xforce.ibmcloud.com/vulnerabilities/59267




© 1998-2025 E-Soft Inc. All rights reserved.