SMTP: Microsoft Help Center Input Validation Vulnerability
This signature detects e-mail containing invalid HTTP links to the Microsoft Help Center. Attackers can exploit a known input validation vulnerability in Help and Support Center, by sending a victim a specially formatted HSC URL in an e-mail. This vulnerability affects Windows XP prior to service pack 2, and the Windows 2003 Server.
Extended Description
Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).
Affected Products
Microsoft windows_xp
References
BugTraq: 10321
CVE: CVE-2004-0199
URL: http://www.microsoft.com/technet/security/bulletin/ms04-015.mspx http://www.kb.cert.org/vuls/id/484814
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Microsoft
5.1