CVE-2003-0907

Windows XP SP1 and Windows Server 2003 - Remote Code Execution via HCP URL Argument Injection

Title source: llm
STIX 2.1

Description

Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.

References (11)

Core 11
Core References
Broken Link third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/o-114.shtml
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/260588
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10119
Patch, Vendor Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011
Broken Link, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Third Party Advisory mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108196864221676&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15704

Scores

EPSS 0.2185
EPSS Percentile 97.3%

Details

CWE
CWE-88
Status published
Products (2)
microsoft/windows_server_2003
microsoft/windows_xp
Published Jun 01, 2004
Tracked Since Feb 18, 2026