PT-2012-1304 · Microsoft+1 · Help/Support Center+1

Published

2012-08-22

·

Updated

2012-08-22

·

CVE-2010-3499

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions F-Secure Anti-Virus (affected versions not specified)
Description The issue arises from the improper interaction between F-Secure Anti-Virus and the Microsoft Help and Support Center's processing of hcp:// URLs. This makes it easier for remote attackers to execute arbitrary code via malware, even if the malware is correctly detected by the product. The detection approach occurs too late to stop the code execution. It has been noted that the vendor response attributes the inability to catch these files to lacking functionality rather than programming errors.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3499

Affected Products

F-Secure Anti-Virus
Help/Support Center