← back
CVE-2010-1885observed exploitation

CVE-2010-1885

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 75%
from disclosure to weapon0 days
Published on NVDJun 14
1st PoCJun 10
metasploitJun 9
VulnCheck+407d
exploitation probability
75%top 1% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist (fromHCP option) and execute arbitrary commands via a crafted hcp:// URL, aka "Help Center URL Validation Vulnerability."
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.