{"api_version":"1","generated_at":"2026-07-23T11:49:51+00:00","cve":"CVE-2010-0483","urls":{"html":"https://cve.report/CVE-2010-0483","api":"https://cve.report/api/cve/CVE-2010-0483.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-0483","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-0483"},"summary":{"title":"CVE-2010-0483","description":"vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka \"VBScript Help Keypress Vulnerability.\"","state":"PUBLISHED","assigner":"microsoft","published_at":"2010-03-03 19:30:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-94","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.6","severity":"","vector":"AV:N/AC:H/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:C/I:C/A:C","baseScore":7.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56558","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56558","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/38463","name":"http://www.securityfocus.com/bid/38463","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Microsoft VBScript 'winhlp32.exe' 'MsgBox()' Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://blogs.technet.com/msrc/archive/2010/03/01/security-advisory-981169-released.aspx","name":"http://blogs.technet.com/msrc/archive/2010/03/01/security-advisory-981169-released.aspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"The Microsoft Security Response Center (MSRC) : Security Advisory 981169 Released","mime":"text/html","httpstatus":"503","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/0485","name":"http://www.vupen.com/english/advisories/2010/0485","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/612021","name":"http://www.kb.cert.org/vuls/id/612021","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#612021","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.metasploit.com/svn/framework3/trunk/modules/exploits/windows/browser/ie_winhlp32.rb","name":"https://www.metasploit.com/svn/framework3/trunk/modules/exploits/windows/browser/ie_winhlp32.rb","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Metasploit | Penetration Testing Software, Pen Testing Security | Metasploit","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://securitytracker.com/id?1023668","name":"http://securitytracker.com/id?1023668","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker: Windows VBScript Script Engine Flaw in Processing Windows Help Files Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-022","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-022","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS10-022 - Important | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA10-103A.html","name":"http://www.us-cert.gov/cas/techalerts/TA10-103A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA10-103A -- Microsoft Updates for Multiple Vulnerabilities","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7170","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7170","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://isec.pl/vulnerabilities/isec-0027-msgbox-helpfile-ie.txt","name":"http://isec.pl/vulnerabilities/isec-0027-msgbox-helpfile-ie.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://isec.pl/vulnerabilities10.html","name":"http://isec.pl/vulnerabilities10.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"iSEC Security Research : : Vulnerabilities 2010","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.microsoft.com/technet/security/advisory/981169.mspx","name":"http://www.microsoft.com/technet/security/advisory/981169.mspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Microsoft Security Advisory (981169): Vulnerability in VBScript Could Allow Remote Code Execution","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"http://www.osvdb.org/62632","name":"http://www.osvdb.org/62632","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.computerworld.com/s/article/9163298/New_zero_day_involves_IE_puts_Windows_XP_users_at_risk","name":"http://www.computerworld.com/s/article/9163298/New_zero_day_involves_IE_puts_Windows_XP_users_at_risk","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"New zero-day involves IE, puts Windows XP users at risk","mime":"application/octet-stream","httpstatus":"200","archivestatus":"200"},{"url":"http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx","name":"http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Investigating a new win32hlp and Internet Explorer issue - The Microsoft Security Response Center (MSRC) - Site Home - TechNet Blogs","mime":"text/html","httpstatus":"503","archivestatus":"200"},{"url":"http://secunia.com/advisories/38727","name":"http://secunia.com/advisories/38727","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Microsoft Windows \"MsgBox()\" HLP File Execution Vulnerability - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8654","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8654","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://blogs.technet.com/srd/archive/2010/03/01/help-keypress-vulnerability-in-vbscript-enabling-remote-code-execution.aspx","name":"http://blogs.technet.com/srd/archive/2010/03/01/help-keypress-vulnerability-in-vbscript-enabling-remote-code-execution.aspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Help keypress vulnerability in VBScript enabling Remote Code Execution - Security Research & Defense - Site Home - TechNet Blogs","mime":"text/html","httpstatus":"503","archivestatus":"200"},{"url":"http://www.theregister.co.uk/2010/03/01/ie_code_execution_bug/","name":"http://www.theregister.co.uk/2010/03/01/ie_code_execution_bug/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IE code execution bug can bite older Windows • The Register","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-0483","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-0483","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"483","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"483","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"483","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"483","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2000","cpe6":"*","cpe7":"sp4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"483","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"*","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"483","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"*","cpe7":"sp2","cpe8":"itanium","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"483","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2003","cpe6":"*","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"483","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"*","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"483","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"*","cpe7":"sp3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"483","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"-","cpe7":"sp2","cpe8":"x64","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T00:52:18.731Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"oval:org.mitre.oval:def:7170","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7170"},{"name":"ms-win-msgbox-code-execution(56558)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56558"},{"name":"MS10-022","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-022"},{"name":"VU#612021","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/612021"},{"name":"62632","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/62632"},{"name":"ADV-2010-0485","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0485"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.computerworld.com/s/article/9163298/New_zero_day_involves_IE_puts_Windows_XP_users_at_risk"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.microsoft.com/technet/security/advisory/981169.mspx"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.theregister.co.uk/2010/03/01/ie_code_execution_bug/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://isec.pl/vulnerabilities/isec-0027-msgbox-helpfile-ie.txt"},{"name":"38463","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/38463"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://isec.pl/vulnerabilities10.html"},{"name":"oval:org.mitre.oval:def:8654","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8654"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://blogs.technet.com/srd/archive/2010/03/01/help-keypress-vulnerability-in-vbscript-enabling-remote-code-execution.aspx"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.metasploit.com/svn/framework3/trunk/modules/exploits/windows/browser/ie_winhlp32.rb"},{"name":"1023668","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1023668"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://blogs.technet.com/msrc/archive/2010/03/01/security-advisory-981169-released.aspx"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx"},{"name":"TA10-103A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA10-103A.html"},{"name":"38727","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38727"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-02-26T00:00:00.000Z","descriptions":[{"lang":"en","value":"vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka \"VBScript Help Keypress Vulnerability.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-12T19:57:01.000Z","orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft"},"references":[{"name":"oval:org.mitre.oval:def:7170","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7170"},{"name":"ms-win-msgbox-code-execution(56558)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56558"},{"name":"MS10-022","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-022"},{"name":"VU#612021","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/612021"},{"name":"62632","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/62632"},{"name":"ADV-2010-0485","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0485"},{"tags":["x_refsource_MISC"],"url":"http://www.computerworld.com/s/article/9163298/New_zero_day_involves_IE_puts_Windows_XP_users_at_risk"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.microsoft.com/technet/security/advisory/981169.mspx"},{"tags":["x_refsource_MISC"],"url":"http://www.theregister.co.uk/2010/03/01/ie_code_execution_bug/"},{"tags":["x_refsource_MISC"],"url":"http://isec.pl/vulnerabilities/isec-0027-msgbox-helpfile-ie.txt"},{"name":"38463","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/38463"},{"tags":["x_refsource_MISC"],"url":"http://isec.pl/vulnerabilities10.html"},{"name":"oval:org.mitre.oval:def:8654","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8654"},{"tags":["x_refsource_CONFIRM"],"url":"http://blogs.technet.com/srd/archive/2010/03/01/help-keypress-vulnerability-in-vbscript-enabling-remote-code-execution.aspx"},{"tags":["x_refsource_MISC"],"url":"https://www.metasploit.com/svn/framework3/trunk/modules/exploits/windows/browser/ie_winhlp32.rb"},{"name":"1023668","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1023668"},{"tags":["x_refsource_CONFIRM"],"url":"http://blogs.technet.com/msrc/archive/2010/03/01/security-advisory-981169-released.aspx"},{"tags":["x_refsource_CONFIRM"],"url":"http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx"},{"name":"TA10-103A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA10-103A.html"},{"name":"38727","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38727"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@microsoft.com","ID":"CVE-2010-0483","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka \"VBScript Help Keypress Vulnerability.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"oval:org.mitre.oval:def:7170","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7170"},{"name":"ms-win-msgbox-code-execution(56558)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/56558"},{"name":"MS10-022","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-022"},{"name":"VU#612021","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/612021"},{"name":"62632","refsource":"OSVDB","url":"http://www.osvdb.org/62632"},{"name":"ADV-2010-0485","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/0485"},{"name":"http://www.computerworld.com/s/article/9163298/New_zero_day_involves_IE_puts_Windows_XP_users_at_risk","refsource":"MISC","url":"http://www.computerworld.com/s/article/9163298/New_zero_day_involves_IE_puts_Windows_XP_users_at_risk"},{"name":"http://www.microsoft.com/technet/security/advisory/981169.mspx","refsource":"CONFIRM","url":"http://www.microsoft.com/technet/security/advisory/981169.mspx"},{"name":"http://www.theregister.co.uk/2010/03/01/ie_code_execution_bug/","refsource":"MISC","url":"http://www.theregister.co.uk/2010/03/01/ie_code_execution_bug/"},{"name":"http://isec.pl/vulnerabilities/isec-0027-msgbox-helpfile-ie.txt","refsource":"MISC","url":"http://isec.pl/vulnerabilities/isec-0027-msgbox-helpfile-ie.txt"},{"name":"38463","refsource":"BID","url":"http://www.securityfocus.com/bid/38463"},{"name":"http://isec.pl/vulnerabilities10.html","refsource":"MISC","url":"http://isec.pl/vulnerabilities10.html"},{"name":"oval:org.mitre.oval:def:8654","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8654"},{"name":"http://blogs.technet.com/srd/archive/2010/03/01/help-keypress-vulnerability-in-vbscript-enabling-remote-code-execution.aspx","refsource":"CONFIRM","url":"http://blogs.technet.com/srd/archive/2010/03/01/help-keypress-vulnerability-in-vbscript-enabling-remote-code-execution.aspx"},{"name":"https://www.metasploit.com/svn/framework3/trunk/modules/exploits/windows/browser/ie_winhlp32.rb","refsource":"MISC","url":"https://www.metasploit.com/svn/framework3/trunk/modules/exploits/windows/browser/ie_winhlp32.rb"},{"name":"1023668","refsource":"SECTRACK","url":"http://securitytracker.com/id?1023668"},{"name":"http://blogs.technet.com/msrc/archive/2010/03/01/security-advisory-981169-released.aspx","refsource":"CONFIRM","url":"http://blogs.technet.com/msrc/archive/2010/03/01/security-advisory-981169-released.aspx"},{"name":"http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx","refsource":"CONFIRM","url":"http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx"},{"name":"TA10-103A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA10-103A.html"},{"name":"38727","refsource":"SECUNIA","url":"http://secunia.com/advisories/38727"}]}}}},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2010-0483","datePublished":"2010-03-03T19:00:00.000Z","dateReserved":"2010-02-02T00:00:00.000Z","dateUpdated":"2024-08-07T00:52:18.731Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-03-03 19:30:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-94","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:C/I:C/A:C","baseScore":7.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":4.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*","matchCriteriaId":"83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*","matchCriteriaId":"2978BF86-5A1A-438E-B81F-F360D0E30C9C"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:*:sp2:itanium:*:*:*:*:*","matchCriteriaId":"F7EFB032-47F4-4497-B16B-CB9126EAC9DF"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*","matchCriteriaId":"4D3B5E4F-56A6-4696-BBB4-19DF3613D020"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*","matchCriteriaId":"9B339C33-8896-4896-88FF-88E74FDBC543"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*","matchCriteriaId":"CE477A73-4EE4-41E9-8694-5A3D5DC88656"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_xp:-:sp2:x64:*:*:*:*:*","matchCriteriaId":"FFAC3F90-77BF-4F56-A89B-8A3D2D1FC6D6"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*","matchCriteriaId":"693D3C1C-E3E4-49DB-9A13-44ADDFF82507"},{"vulnerable":false,"criteria":"cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:*","matchCriteriaId":"1A33FA7F-BB2A-4C66-B608-72997A2BD1DB"},{"vulnerable":false,"criteria":"cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*","matchCriteriaId":"A52E757F-9B41-43B4-9D67-3FEDACA71283"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"483","Ordinal":"1","Title":"CVE-2010-0483","CVE":"CVE-2010-0483","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"483","Ordinal":"1","NoteData":"vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka \"VBScript Help Keypress Vulnerability.\"","Type":"Description","Title":"CVE-2010-0483"},{"CveYear":"2010","CveId":"483","Ordinal":"2","NoteData":"2010-03-03","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"483","Ordinal":"3","NoteData":"2018-10-12","Type":"Other","Title":"Modified"}]}}}