SmartDefense Security Advisory

Microsoft Internet Explorer Help and Support Center Remote Code Execution Vulnerability

Industry Reference:CVE-2010-1885.

A remote code execution vulnerability has been discovered in the Windows Help and Support Center. The Help and Support Center (HSC) is a feature in Windows that provides help on a variety of topics. HSC enables users to learn about Windows features, download and install software updates, get assistance from Microsoft and so forth. A remote attacker could exploit this issue by convincing a user to open a maliciously crafted HTML file with Internet Explorer, which may allow the attacker to execute arbitrary code on the affected system. This protection will detect and block attempts to exploit this vulnerability.

Security Gateway R70/R71: A new protection is now available.
VPN-1 NGX R65 & VSX NGX R65: A new protection is now available.
CPAI-2010-208.

June 13, 2010

IPS Software Blade

Buy Now

Guidelines

Forums

SmartDefense Microsoft Security Resources
You have received this notification because you have subscribed to the SmartDefense mailing list. If you would prefer to no longer receive security alerts and defense notifications please click to Unsubscribe

As always, please feel free to contact us directly if you have any comments or questions.

Read Check Point's Privacy Policy
©2003.2009 Check Point Software Technologies Ltd. (Nasdaq: CHKP) All rights reserved.
800 Bridge Parkway, Redwood City, CA USA 94065