PT-2010-3851 · Microsoft · Windows Help/Support Center+2

Tavis Ormandy

·

Publicado

2010-06-14

·

Atualizado

2019-02-26

·

CVE-2010-2265

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Windows Help and Support Center versions for Windows XP and Windows Server 2003
Description A cross-site scripting (XSS) issue exists in the GetServerName function, allowing remote attackers to inject arbitrary web script or HTML via the svr parameter to "sysinfo/sysinfomain.htm". This can potentially be used to execute arbitrary commands without user interaction when combined with other vulnerabilities.
Recommendations For Microsoft Windows Help and Support Center versions for Windows XP and Windows Server 2003, consider restricting access to the "sysinfo/sysinfomain.htm" endpoint until a fix is available. As a temporary workaround, avoid using the svr parameter in the affected API endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2265

Produtos afetados

Windows Help/Support Center
Windows Server 2003
Windows Xp