Korean
<< Back
VID 26500
Severity 30
Port 139,445
Protocol TCP
Class SMB
Detailed Description The Hotfix (MS10-022, 981169) for 'Vulnerability in VBScript Scripting Engine Could Allow Remote Code Execution' has not been applied.
The vulnerability could allow remote code execution if a malicious Web site displayed a specially crafted dialog box on a Web page and a user pressed the F1 key, causing the Windows Help System to be started with a Windows Help File provided by the attacker. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system.

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://www.microsoft.com/technet/security/bulletin/ms10-022.mspx

* Platforms Affected:
Windows 2000 Service Pack 4
Windows XP SP2 and SP3
Windows Server 2003 SP2
Windows Vista, SP1 and SP2
Windows Server 2008 and SP2
Windows 7
Recommendation Apply the appropriate patch (981169) for your system, as listed in Microsoft Security Bulletin MS10-022 at http://www.microsoft.com/technet/security/bulletin/ms10-022.mspx
Related URL CVE-2010-0234,CVE-2010-0235,CVE-2010-0236,CVE-2010-0237,CVE-2010-0238,CVE-2010-0481,CVE-2010-0482,CVE-2010-0810 (CVE)
Related URL 39297,39309,39318,39319,39320,39322,39323,39324 (SecurityFocus)
Related URL (ISS)