5.1
CVE-2004-0199
- EPSS 26.13%
- Veröffentlicht 14.06.2004 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:05:08
- Erkennungen
Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2003 Server Version enterprise Edition 64-bit
Microsoft ≫ Windows 2003 Server Version enterprise_64-bit
Microsoft ≫ Windows 2003 Server Version r2
Microsoft ≫ Windows 2003 Server Version r2 Edition 64-bit
Microsoft ≫ Windows 2003 Server Version r2 Edition datacenter_64-bit
Microsoft ≫ Windows 2003 Server Version standard Edition 64-bit
Microsoft ≫ Windows 2003 Server Version web
Microsoft ≫ Windows Xp Edition 64-bit
Microsoft ≫ Windows Xp Edition home
Microsoft ≫ Windows Xp Update gold
Microsoft ≫ Windows Xp Update gold Edition professional
Microsoft ≫ Windows Xp Update sp1 Edition 64-bit
Microsoft ≫ Windows Xp Update sp1 Edition home
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 26.13% | 0.977 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.1 | 4.9 | 6.4 |
AV:N/AC:H/Au:N/C:P/I:P/A:P
|
http://marc.info/?l=bugtraq&m=108437759930820&w=2
http://marc.info/?l=full-disclosure&m=108430407801825&w=2
http://www.exploitlabs.com/files/advisories/EXPL-A-2004-001-helpctr.txt
http://www.kb.cert.org/vuls/id/484814
http://www.securityfocus.com/bid/10321
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-015
https://exchange.xforce.ibmcloud.com/vulnerabilities/16095
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1008
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1032