First published: Thu May 20 2004(Updated: )
Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" argument to the topic parameter in an hcp:// URL. NOTE: since the initial report of this problem, several researchers have been unable to reproduce this issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =sp1 | |
Microsoft Windows XP | =gold | |
Microsoft Windows XP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0474 is considered a moderate severity vulnerability that may allow unauthorized file access.
To mitigate CVE-2004-0474, users should apply security updates or consider upgrading from affected versions of Windows XP.
CVE-2004-0474 affects various versions of Windows XP, including SP1 and the initial release.
Yes, CVE-2004-0474 can be exploited remotely through specially crafted hcp:// URLs.
While CVE-2004-0474 is an older vulnerability, using unpatched systems remains a risk if in operation.