Tavis Ormandy released an exploit for the “Windows Help Center” of Windows XP ServicePack 2 and ServicePack 3.
By just clicking on an malicious link you can get exploited by an attacker.

The exploit uses a security hole in the Help Center of Windows XP. It’s a Cross-Site Script attack. For further informations goto:

To prevent yourself against this attack Microsoft say you should delete the association in your registry.
The next lines and the video shows how this attacks looks like and for some of you how to use it ;)

  1. update Metasploit to rev. r9513
  2. use windows/browser/ms10_xxx_helpctr_xss_cmd_exec as exploit
  3. set your payload
  4. set options like LHOST and LPORT
  5. fire up the exploit
  6. trick the victim to get on the malicious site
  7. GAME OVER

This Video show how to exploit the target

Vulnerability in Windows Help Center CVE-2010-1885 from hardez on Vimeo.

To prevent yourself against this attack do the following steps:

  1. create a new text file on you desktop
  2. open it an past the following text

    Windows Registry Editor Version 5.00

    [-HKEY_CLASSES_ROOT\HCP]

  3. save this file as helpcenter.reg and choose as fileformat all files
  4. open the file
  5. now your safe

and this show how to prevent against the attack

How to prevent against Vulnerability in Windows Help Center CVE-2010-1885 from hardez on Vimeo.

Tagged with:  

3 Responses to “Vulnerability in Windows Help Center CVE-2010-1885 (MS10-042)”

  1. jhon says:

    cooooooooool
    but what the name of the song ??
    greet site

  2. hardez says:

    It was from jamendo.com but this time I forgot to note the artist.
    I will post it on monday!

Leave a Reply