Microsoft Help and Support Center 'sysinfo/sysinfomain.htm' Cross Site Scripting Weakness
BID:40721
Info
Microsoft Help and Support Center 'sysinfo/sysinfomain.htm' Cross Site Scripting Weakness
| Bugtraq ID: | 40721 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-2265 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Tavis Ormandy |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition SP3 Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Tablet PC Edition SP1 Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional SP3 Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition SP3 Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP3 Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows Server 2003 Web Edition SP2 Microsoft Windows Server 2003 Web Edition SP1 Beta 1 Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition SP2 Microsoft Windows Server 2003 Standard Edition SP1 Beta 1 Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 Itanium SP1 Microsoft Windows Server 2003 Itanium 0 Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition SP1 Beta 1 Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows Server 2003 R2 Platfom SDK |
| Not Vulnerable: | |
Discussion
Microsoft Help and Support Center 'sysinfo/sysinfomain.htm' Cross Site Scripting Weakness
Help and Support Center is prone to a cross-site scripting weakness because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the privileged zone of the browser of an unsuspecting user.
NOTE: This issue is a weakness because the affected file is only accessible by trusted sources unless other vulnerabilities, such as BID 40725 (Microsoft Windows Help And Support Center Trusted Document Whitelist Bypass Vulnerability) are used to bypass the restrictions. This weakness may then be used to execute script code in the privileged zone of the browser by unauthorized sites.
Help and Support Center is prone to a cross-site scripting weakness because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the privileged zone of the browser of an unsuspecting user.
NOTE: This issue is a weakness because the affected file is only accessible by trusted sources unless other vulnerabilities, such as BID 40725 (Microsoft Windows Help And Support Center Trusted Document Whitelist Bypass Vulnerability) are used to bypass the restrictions. This weakness may then be used to execute script code in the privileged zone of the browser by unauthorized sites.
Exploit / POC
Microsoft Help and Support Center 'sysinfo/sysinfomain.htm' Cross Site Scripting Weakness
Microsoft reported that this issue is being exploited in limited attacks in the wild.
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following example URI is available:
hcp://system/sysinfo/sysinfomain.htm?svr=<h1>test</h1>
Microsoft reported that this issue is being exploited in limited attacks in the wild.
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following example URI is available:
hcp://system/sysinfo/sysinfomain.htm?svr=<h1>test</h1>
Solution / Fix
Microsoft Help and Support Center 'sysinfo/sysinfomain.htm' Cross Site Scripting Weakness
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Help and Support Center 'sysinfo/sysinfomain.htm' Cross Site Scripting Weakness
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly (Tavis Ormandy)