| Patch Name : |
Q811630_WXP_SP2_x86_ENU.exe |
| Patch Description : |
|
| Bulletin Id : |
MSWU-006 |
| Bulletin Title : |
HTML Help Update to Limit Functionality When It Is Invoked with the window.showHelp( ) Method (811630). |
| KnowledgeBase : | 811630 |
| Severity : |
Unrated |
| Location Path : | Q811630_WXP_SP2_x86_ENU.exe |
| Bulletin Summary: |
Either of the following symptoms may occur when you use Microsoft Internet Explorer to open or use a Web page that calls the window.showHelp script method to open a Uniform Resource Locator (URL) in an HTML Help window:
? The URL that is specified by the window.showHelp method does not appear in the HTML Help window after you install the February 2003 Cumulative Patch for Internet Explorer (MS03-004).
? If you have not installed the February 2003 Cumulative Patch for Internet Explorer (MS03-004), an attacker may be able to host a Web page that calls the window.showHelp method to open an URL in another domain in the HTML Help window. This may permit the attacker access the data that the Web site of that URL contains.
With the window.showHelp method, you can also open an HTML Help (.chm) file that contains a shortcut. A shortcut is a command that the HTML Help ActiveX control supports. The command opens a program file from the Help topic. If you have not installed the February 2003 Cumulative Patch for Internet Explorer (MS03-004), and other vulnerabilities exist that permit an attacker to have write access to the data that is in the HTML Help topic window, the attacker might use the shortcut command to run code in the user's security context. |
| Superceding Bulletin Id : |
None |
| Patch Release Date : |
Jan 1, 1970 |
| CVE Id : | |
| Affected Product Information |
|
| Product Name |
Service Pack Name |
| Windows XP Professional | Windows XP Gold |
| Windows XP Professional | Windows XP Service Pack 1 |
|
| File changes |
|
| File Path |
Version |
| %Windir%\Hh.exe | 5.2.3644.0 |
| %windir%\system32\Hhctrl.ocx | 5.2.3735.0 |
| %windir%\system32\Hhsetup.dll | 5.2.3644.0 |
| %windir%\system32\Itircl.dll | 5.2.3644.0 |
| %windir%\system32\Itss.dll | 5.2.3644.0 |
|
| Registry changes |
|
| Registry Path |
Key Name |
Key Value |
| No records found | | |