VID |
26500 |
Severity |
30 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
The Hotfix (MS10-022, 981169) for 'Vulnerability in VBScript Scripting Engine Could Allow Remote Code Execution' has not been applied. The vulnerability could allow remote code execution if a malicious Web site displayed a specially crafted dialog box on a Web page and a user pressed the F1 key, causing the Windows Help System to be started with a Windows Help File provided by the attacker. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system.
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: http://www.microsoft.com/technet/security/bulletin/ms10-022.mspx
* Platforms Affected: Windows 2000 Service Pack 4 Windows XP SP2 and SP3 Windows Server 2003 SP2 Windows Vista, SP1 and SP2 Windows Server 2008 and SP2 Windows 7 |
Recommendation |
Apply the appropriate patch (981169) for your system, as listed in Microsoft Security Bulletin MS10-022 at http://www.microsoft.com/technet/security/bulletin/ms10-022.mspx |
Related URL |
CVE-2010-0234,CVE-2010-0235,CVE-2010-0236,CVE-2010-0237,CVE-2010-0238,CVE-2010-0481,CVE-2010-0482,CVE-2010-0810 (CVE) |
Related URL |
39297,39309,39318,39319,39320,39322,39323,39324 (SecurityFocus) |
Related URL |
(ISS) |
|