Version: 2008
  • On MovieTome: See the villain of IRON MAN 2!
advertisement
Click Here

Microsoft Security Bulletin MS03-006 812709

  • Quick specs
  • Price: Update
  • Operating system:
  • Date added: February 26, 2003
  • Total Downloads: 12
  • Downloads last week: 1
  • See full specifications
Add to my list Add to my Watch List
Tested spyware free

Publisher's description

From Microsoft :

Help and Support Center provides a centralized facility through which users can obtain assistance on a variety of topics. For instance, it provides product documentation, assistance in determining hardware compatibility, access to Windows Update, online help from Microsoft, and other assistance. Users and programs can execute URL links to Help and Support Center by using the "hcp://" prefix in a URL link instead of "http://".

A security vulnerability is present in the Windows Me version of Help and Support Center, and results because the URL Handler for the "hcp://" prefix contains an unchecked buffer.

An attacker could exploit the vulnerability by constructing a URL that, when clicked on by the user, would execute code of the attacker?s choice in the Local Computer security context. The URL could be hosted on a web page, or sent directly to the user in email. In the web based scenario, where a user then clicked on the URL hosted on a website, an attacker could have the ability to read or launch files already present on the local machine. In the case of an e-mail borne attack, if the user was using Outlook Express 6.0 or Outlook 2002 in their default configurations, or Outlook 98 or 2000 in conjunction with the Outlook Email Security Update, then an attack could not be automated and the user would still need to click on a URL sent in e-mail. However if the user was not using Outlook Express 6.0 or Outlook 2002 in their default configurations, or Outlook 98 or 2000 in conjunction with the Outlook Email Security Update, the attacker could cause an attack to trigger automatically without the user having to click on a URL contained in an e-mail.

Convert video files between various video & audio formats.

More popular Operating Systems & Updates downloads

  1. 53,112 downloads 1. CNET TechTracker app
  2. 21,805 downloads 2. DriverMax
  3. 7,757 downloads 3. Windows 7 USB/DVD Download Tool
  4. 5,684 downloads 4. Windows XP Media Center Edition
  5. 5,568 downloads 5. Windows XP Service Pack 3
  6. See all Operating Systems & Updates downloads
Because what good is a new computer without the right software?

User reviews

Write your own review Be the first one to review Microsoft Security Bulletin MS03-006 812709 and share your experience with the CNET community!

Submit your review

Log in or create an account to submit your review for:

Microsoft Security Bulletin MS03-006 812709

ORLog in with your Facebook account
1. Rate this product:
(Mouse over the stars to rate this product and click to set your rating.)
2. One-line summary:(Summarize your review in one line. 10 characters minimum; required.)
0 of 55 characters
3. Pros:(Tell us what you like about this product. 10 characters minimum; required.)
0 of 250 characters
4. Cons:(Tell us what you don't like about this product. 10 characters minimum; required.)
0 of 250 characters
Bottom-line summary:(Explain to us in detail why you like or dislike the product, focusing your comments on the product's features and functionality, and your experience using the product. This field is optional.)
0 of 5000 characters

The posting of advertisements, profanity, or personal attacks are prohibited.
Click here to review our site terms of use.

Submit
See more CNET content tagged:
Microsoft Outlook,
Microsoft Outlook 2002,
Microsoft Outlook 98,
Microsoft Outlook Express 6.0,
attacker

advertisement