PT-2012-1304 · Microsoft+1 · Help/Support Center+1
Published
2012-08-22
·
Updated
2012-08-22
·
CVE-2010-3499
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
F-Secure Anti-Virus (affected versions not specified)
Description
The issue arises from the improper interaction between F-Secure Anti-Virus and the Microsoft Help and Support Center's processing of hcp:// URLs. This makes it easier for remote attackers to execute arbitrary code via malware, even if the malware is correctly detected by the product. The detection approach occurs too late to stop the code execution. It has been noted that the vendor response attributes the inability to catch these files to lacking functionality rather than programming errors.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
F-Secure Anti-Virus
Help/Support Center