Flaw in Windows Me Help and Support Center Could Enable Code Execution

Published by

Microsoft Security Bulletin MS03-006 : A security vulnerability is present in the Windows Me version of Help and Support Center, and results because the URL Handler for the "hcp://" prefix contains an unchecked buffer.

An attacker could exploit the vulnerability by constructing a URL that, when clicked on by the user, would execute code of the attacker?s choice in the Local Computer security context. The URL could be hosted on a web page, or sent directly to the user in email. This issue affects Windows Me only. Users running other versions of Windows do not need this update.