CVE-2004-0474

Windows XP - Arbitrary File Read and Execution via Help Center URL Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-0474. PoCs published by Bartosz Kwitkowski.

AI-analyzed exploit summary The provided text describes a vulnerability in the Microsoft Windows XP HCP URI handler that allows arbitrary command execution via specially crafted URIs. It includes examples of exploit vectors but lacks executable code.

Description

Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" argument to the topic parameter in an hcp:// URL. NOTE: since the initial report of this problem, several researchers have been unable to reproduce this issue.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Bartosz Kwitkowski · textremotewindows
https://www.exploit-db.com/exploits/23675

The provided text describes a vulnerability in the Microsoft Windows XP HCP URI handler that allows arbitrary command execution via specially crafted URIs. It includes examples of exploit vectors but lacks executable code.

Classification
Writeup 80%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: Microsoft Windows XP SP1 (Polish versions confirmed)
No auth needed
Prerequisites: User interaction required to follow a malicious link
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0688.html
Exploit mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/353248
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9621
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15101
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0450.html
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=107652584102003&w=2
Exploit, Vendor Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2004-02/0440.html

Scores

EPSS 0.1620
EPSS Percentile 96.5%

Details

Status published
Products (1)
microsoft/windows_xp (3 CPE variants)
Published Jul 07, 2004
Tracked Since Feb 18, 2026