PT-2012-1304 · Microsoft+1 · Help/Support Center+1
Publicado
2012-08-22
·
Atualizado
2012-08-22
·
CVE-2010-3499
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
F-Secure Anti-Virus (affected versions not specified)
Description
The issue arises from the improper interaction between F-Secure Anti-Virus and the Microsoft Help and Support Center's processing of hcp:// URLs. This makes it easier for remote attackers to execute arbitrary code via malware, even if the malware is correctly detected by the product. The detection approach occurs too late to stop the code execution. It has been noted that the vendor response attributes the inability to catch these files to lacking functionality rather than programming errors.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
F-Secure Anti-Virus
Help/Support Center