Short Name |
SMTP:MAL:MS-HSC-DVD-VLN |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
SMTP |
Keywords |
Microsoft Help Center Input Validation Vulnerability |
Release Date |
2004/05/11 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects e-mail containing invalid HTTP links to the Microsoft Help Center. Attackers can exploit a known input validation vulnerability in Help and Support Center, by sending a victim a specially formatted HSC URL in an e-mail. This vulnerability affects Windows XP prior to service pack 2, and the Windows 2003 Server.
A security vulnerability has been reported in Microsoft Windows XP and Server 2003 operating systems. This issue exists in the Help and Support Center (HSC) and is due to how the feature handles HCP invocation URIs for DVD driver upgrades. This issue could be exploited from a malicious web page or HTML e-mail to cause a malicious executable to be run on a vulnerable system. This would occur in the context of the victim user, though it has been reported that significant user interaction is required for exploitation to occur. While this issue may be exploited through Internet Explorer, it should also be noted that third-party web client software could also invoke HSC via a HCP URI.