I have recently received this alert:
CVE-2010-0483
(under review) |
Learn more at National Vulnerability Database (NVD)
• Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings |
| Description |
| vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe
when the F1 key is pressed, aka "VBScript Help Keypress Vulnerability." |
*****************
Microsoft Security Advisory (981169)
Vulnerability in VBScript Could Allow Remote Code Execution
Published: March 01, 2010 | Updated: April 13, 2010
Version: 2.0
Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS10-022 to address this issue. For more information about this issue, including download links for an available security update, please review MS10-022. The vulnerability addressed is the VBScript Help Keypress Vulnerability - CVE-2010-0483.
**************
Is there a real alert or a hoax?
Good Answers: