Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Windows : Microsoft Bulletins >> Flaw in WinXP Help center could enable file deletion


Vulnerability Assessment Details

Flaw in WinXP Help center could enable file deletion

Vulnerability Assessment Summary
Checks for MS Hotfix Q328940

Detailed Explanation for this Vulnerability Assessment

Summary :

Arbitrary files can be deleted on the remote host through the web client.

Description :

There is a security vulnerability in the remote Windows XP Help and Support
Center which can be exploited by a possible hacker to delete arbitrary file
on this host.

To do so, a possible hacker needs to create malicious web pages that must
be visited by the owner of the remote system.

Solution :

Microsoft has released a set of patches for Windows XP and 2000 :

http://www.microsoft.com/technet/security/bulletin/ms02-060.mspx

Network Security Threat Level:

Medium / CVSS Base Score : 4
(AV:R/AC:H/Au:NR/C:N/A:N/I:C/B:I)

Networks Security ID: 5478

Vulnerability Assessment Copyright: This script is Copyright (C) 2005-2007 Tenable Network Security

Mainframe, DEC, VAX, AS 400

Discussions

No Discussions have been posted on this vulnerability.