Home » Vulnerability

Windows Help Center Application Pose Grave Threat to Windows XP/Server 2003

Submitted by on June 12, 2010 – 8:17 PMNo Comment

“A new vulnerability has been reported to the general public this morning via the “Full-Disclosure” mailing list, and it is quite troubling”, stated by Jonathan Davis, an IT Security Consultant in the Washington DC metro area.  He further stated, “There is a vulnerability that exists in the Windows help center application that is exploitable via many applications and vectors. Most notably it is exploitable via Internet Explorer, allowing a malicious web page to execute any executable file on a user’s system with any flags or parameters they desire. The possibilities for what this could be used for are endless, and the attack doesn’t require any fancy timing attacks or anything that is hard to do at all.”

Here is the link to the original disclosure by the founder of the vulnerability, Tavis Ormandy a Google engineer: http://lists.grok.org.uk/pipermail/full-disclosure/2010-June/074986.html

Microsoft on Thursday confirmed the presence of a zero-day vulnerability stating that it affects Windows XP and Server 2003 systems.  They plan to issue an advisory later to provide workaround guidance to impacted users.

The post outlines some fairly painless workarounds that can be applied via GPO, namely this one:
“Few users rely on Help Center urls (hcp://), it is safe to temporarily disable them by removing HKCR\HCP\shell\open. This modification can be deployed easily using GPOs. For more information on Group Policy, see Microsoft’s Group
Policy site”

Users and companies are currently awaiting a fix.

Sources:

http://www.theinquirer.net/inquirer/news/1676668/xp-help-center-security-flaw-leaves-machines-wide

http://www.eweek.com/c/a/Security/Windows-XP-ZeroDay-Targeted-by-Hackers-in-Driveby-Attack-817982/

http://www/pcworld.com

Share

Leave a comment!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.