Microsoft Windows XP comes with a "Help and Support Center" containing a flaw that allows remote attackers to delete arbitrary files. The flaw is due to the HCP URI handler (hcp://) included with Internet Explorer on XP systems. If an attacker creates a malicious HTML page with a crafted hcp:// call, they can cause a vulnerable system to delete files via the uplddrvinfo.htm page installed with the help center.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Availability
Exploit:
Exploit Rumored
Disclosure:
OSVDB Verified
Solution
Upgrade to version Windows XP SP1 or higher, as it has been reported to fix this vulnerability. Microsoft has also made a patch (Q328940) available to address this issue. It is also possible to correct the flaw by implementing the following workaround: delete or move the uplddrvinfo.htm file.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.