Vulnerabilities > CVE-2004-0474 - Unspecified vulnerability in Microsoft Windows XP

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
microsoft
exploit available

Summary

Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" argument to the topic parameter in an hcp:// URL. NOTE: since the initial report of this problem, several researchers have been unable to reproduce this issue.

Vulnerable Configurations

Part Description Count
OS
Microsoft
3

Exploit-Db

descriptionMicrosoft Windows XP HCP URI Handler Arbitrary Command Execution Vulnerability. CVE-2004-0474. Remote exploit for windows platform
idEDB-ID:23675
last seen2016-02-02
modified2004-02-09
published2004-02-09
reporterBartosz Kwitkowski
sourcehttps://www.exploit-db.com/download/23675/
titleMicrosoft Windows XP HCP URI Handler Arbitrary Command Execution Vulnerability