Proactive IT Security
 

Critical vulnerability in Windows Help and Support Center - update available

2010-06-11 [Software advisories]

A critical vulnerability in Windows Help and Support Center has been identified. Exploitation of this vulnerability could allow remote code execution and take complete control of affected systems.

The following Windows versions are confirmed vulnerable:

  • Windows XP (with Service Packs 2 and 3)
  • Windows Server 2003

Other versions of Windows are not vulnerable according to Microsoft.

As of this writing no updates which remedy the issue are available.

More information in Microsoft Security Advisory 2219475.

This Norman security advisory will be updated when more information is available.

Update 2010-07-13

In its monthly set of security bulletins for July 2010 Microsoft has published updates that address this vulnerability. See Microsoft's Security Bulletin MS10-042 for more information.