MS.Windows.XP.HCP.URI.Handler.Arbitrary.Command.Execution

description-logoDescription

It indicates a possible exploit of Arbitrary Command Execution Vulnerability in Microsoft Windows XP HCP URI Handler.


A vulnerability is reported in Microsoft Windows XP HCP URI Handler that may allow an attacker to execute arbitrary commands on the vulnerable system. This is due to application helpctr.exe failure to sanitize hcp:// URL request. For exploiting this an attacker may by creating a malicious Web page and hosting it on a Web site or by sending it to a victim as an HTML email.

affected-products-logoAffected Products

Microsoft Windows XP Professional SP1.

Impact logoImpact

Compromise of the affected system.

recomended-action-logoRecommended Actions

Apply appropriate service pack path from the Microsoft.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)