Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: May Microsoft Patches Available - SANS Internet Storm Center SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms:

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
May Microsoft Patches Available
May Microsoft Patches Available

Microsoft posted a single security update as part of their regularly scheduled "Second Tuesday of the Month" release. MS04-015, "Vulnerability in Help and Support Center Could Allow Remote Code Execution (840374)" patches an existing vulnerability in the "Help and Support Center" as found in Windows XP and Windows Server 2003.

Because of the way that it handles certain "HCP" URLs, the Help and Support Center is vulnerable to the possibility of remote code execution. The vulnerability could be exploited by a malicious HCP URL and could potentially allow remote code execution. In order for the attack to work, the attacker would only need to convince a user to click on a link to malicious code. Exploiting this vulnerability could allow a malicious attacker to take complete control of an affected system.

According to Microsoft, this issue is rated only as "Important" because they believe that "significant user interaction is required" to exploit the vulnerability.

Further information can be found at:

Also, for more information on the impact of this patch, as well as an update on the latest threats to our networks, join us for the monthly ISC Threat Update webcast, Wednesday, May 12 at 2:00 PM EDT (1800 UTC).

For more information:


Handler on Duty: Tom Liston ( )

160 Posts
May 11th 2004

Sign Up for Free or Log In to start participating in the conversation!