Improper input validation in Microsoft Windows and Windows Server - CVE-2010-1885
Published: January 3, 2017 / Updated: November 20, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to an error when parsing URLs within Microsoft Help and Support Center. A remote attacker can create a specially crafted hcp:// URL, trick the victim into clicking on it and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of the vulnerability results in compromise of vulnerable system.
Note: this vulnerability is being actively exploited.
Affected software
Windows Server
How to mitigate CVE-2010-1885
Links to Public Exploits and PoC-codes
- Exploit #689 - Microsoft Help Center - Cross-Site Scripting / Command Execution (MS10-042) (Metasploit) (March 18, 2020)
- Exploit #690 - Microsoft Windows Help Centre Handles - Malformed Escape Sequences Incorrectly (MS03-044) (March 18, 2020)
- Exploit #1673 - Microsoft Help Center XSS and Command Execution (March 18, 2020)