CVE-2003-0009

Windows Me - Cross-Site Scripting via Help and Support Center Topic Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0009. PoCs published by s0h.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the Microsoft Windows ME Help and Support Center via the HCP URI parameter. It crafts a malicious .CNT file to execute arbitrary code, specifically downloading and executing a trojan from a specified URL.

Description

Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by s0h · cremotewindows
https://www.exploit-db.com/exploits/22289

This exploit targets a buffer overflow vulnerability in the Microsoft Windows ME Help and Support Center via the HCP URI parameter. It crafts a malicious .CNT file to execute arbitrary code, specifically downloading and executing a trojan from a specified URL.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows ME Help and Support Center
No auth needed
Prerequisites: Access to craft or modify a .CNT file · Victim interaction to trigger the exploit
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/n-047.shtml
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/11425.php
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/6074
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=104636383018686&w=2
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/489721
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6966

Scores

EPSS 0.1506
EPSS Percentile 96.3%

Details

Status published
Products (2)
microsoft/windows_me
microsoft/windows_xp (2 CPE variants)
Published Mar 07, 2003
Tracked Since Feb 18, 2026