HIGH
vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka "VBScript Help Keypress Vulnerability."
Published Mar 3, 2010
7.6
HIGHCVSS 2.0
EPSS 86.63%
Description
vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka "VBScript Help Keypress Vulnerability."
Affected products
No data.
AND
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Running on/with
OR
- 6
- 7
- 8
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (21)
- http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx x_refsource_CONFIRMVendor Advisory
- http://blogs.technet.com/msrc/archive/2010/03/01/security-advisory-981169-released.aspx x_refsource_CONFIRMVendor Advisory
- http://blogs.technet.com/srd/archive/2010/03/01/help-keypress-vulnerability-in-vbscript-enabling-remote-code-execution.aspx x_refsource_CONFIRMVendor Advisory
- http://isec.pl/vulnerabilities/isec-0027-msgbox-helpfile-ie.txt x_refsource_MISCExploit
- http://isec.pl/vulnerabilities10.html x_refsource_MISCExploit
- http://secunia.com/advisories/38727 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1023668 vdb-entryx_refsource_SECTRACK
- http://www.computerworld.com/s/article/9163298/New_zero_day_involves_IE_puts_Windows_XP_users_at_risk x_refsource_MISC
- http://www.kb.cert.org/vuls/id/612021 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.microsoft.com/technet/security/advisory/981169.mspx x_refsource_CONFIRMVendor Advisory
- http://www.osvdb.org/62632 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/38463 vdb-entryx_refsource_BIDExploit
- http://www.theregister.co.uk/2010/03/01/ie_code_execution_bug/ x_refsource_MISC
- http://www.us-cert.gov/cas/techalerts/TA10-103A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2010/0485 vdb-entryx_refsource_VUPENVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-022 vendor-advisoryx_refsource_MS
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-0514 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56558 vdb-entryx_refsource_XF
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7170 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8654 vdb-entrysignaturex_refsource_OVAL
- https://www.metasploit.com/svn/framework3/trunk/modules/exploits/windows/browser/ie_winhlp32.rb x_refsource_MISCExploit
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Mar 3, 2010
Updated Aug 7, 2024
Reserved Feb 2, 2010
Link CVE-2010-0483
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2010-0514 Assigner microsoft
Published Mar 3, 2010
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2010-0514