CVE Database
/

CVE-2004-0199

Back to search

CVE-2004-0199

Published: May 14, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).

VendorProductVersions

n/a

n/a

affected
n/a

References

MS04-015
vendor-advisory
x_refsource_MS
win-hcp-code-execution(16095)
vdb-entry
x_refsource_XF
10321
vdb-entry
x_refsource_BID
oval:org.mitre.oval:def:1008
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:1032
vdb-entry
signature
x_refsource_OVAL
VU#484814
third-party-advisory
x_refsource_CERT-VN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now