|
Microsoft Windows Help And Support Center URI Handler Buffer Overflow Vulnerability
Microsoft Help and Support Center (HSC) contains a URI handler that allows pages to be opened through an 'hcp://' prefix. A buffer overflow vulnerability has been reported to affect the Help and Support Center for Microsoft Windows systems. The issue has been reported to present itself due to a lack of sufficient bounds checking performed when handling 'hcp://' URI links. This could allow an unusually long string supplied to the HSC through the URI handler to overrun the bounds of a reserved buffer in memory. A remote attacker may ultimately leverage this condition to have arbitrary code executed in the local computer security context. |
|
|
Privacy Statement |