CVE-2010-0483
Summary
| CVE | CVE-2010-0483 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-03-03 19:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka "VBScript Help Keypress Vulnerability." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:H/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Internet Explorer | 6 | All | All | All |
| Application | Microsoft | Internet Explorer | 7 | All | All | All |
| Application | Microsoft | Internet Explorer | 8 | All | All | All |
| Operating System | Microsoft | Windows 2000 | All | sp4 | All | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp2 | All | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp2 | itanium | All |
| Operating System | Microsoft | Windows Server 2003 | All | sp2 | All | All |
| Operating System | Microsoft | Windows Xp | All | sp2 | All | All |
| Operating System | Microsoft | Windows Xp | All | sp3 | All | All |
| Operating System | Microsoft | Windows Xp | - | sp2 | x64 | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Microsoft VBScript 'winhlp32.exe' 'MsgBox()' Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| The Microsoft Security Response Center (MSRC) : Security Advisory 981169 Released | af854a3a-2127-422b-91ae-364da2661108 | blogs.technet.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| US-CERT Vulnerability Note VU#612021 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Metasploit | Penetration Testing Software, Pen Testing Security | Metasploit | af854a3a-2127-422b-91ae-364da2661108 | www.metasploit.com | Exploit |
| SecurityTracker: Windows VBScript Script Engine Flaw in Processing Windows Help Files Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Microsoft Security Bulletin MS10-022 - Important | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| US-CERT Technical Cyber Security Alert TA10-103A -- Microsoft Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| isec.pl/vulnerabilities/isec-0027-msgbox-helpfile-ie.txt | af854a3a-2127-422b-91ae-364da2661108 | isec.pl | Exploit |
| iSEC Security Research : : Vulnerabilities 2010 | af854a3a-2127-422b-91ae-364da2661108 | isec.pl | Exploit |
| Microsoft Security Advisory (981169): Vulnerability in VBScript Could Allow Remote Code Execution | af854a3a-2127-422b-91ae-364da2661108 | www.microsoft.com | Vendor Advisory |
| www.osvdb.org/62632 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| New zero-day involves IE, puts Windows XP users at risk | af854a3a-2127-422b-91ae-364da2661108 | www.computerworld.com | |
| Investigating a new win32hlp and Internet Explorer issue - The Microsoft Security Response Center (MSRC) - Site Home - TechNet Blogs | af854a3a-2127-422b-91ae-364da2661108 | blogs.technet.com | Vendor Advisory |
| Microsoft Windows "MsgBox()" HLP File Execution Vulnerability - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Help keypress vulnerability in VBScript enabling Remote Code Execution - Security Research & Defense - Site Home - TechNet Blogs | af854a3a-2127-422b-91ae-364da2661108 | blogs.technet.com | Vendor Advisory |
| IE code execution bug can bite older Windows • The Register | af854a3a-2127-422b-91ae-364da2661108 | www.theregister.co.uk | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.