MS.IE.VBScript.Malicious.HLP.File

NameMS.IE.VBScript.Malicious.HLP.File.Command.Execution
Release DateMar 03, 2010
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a command execution vulnerability in
Microsoft Internet Explorer.

The vulnerability is caused by an error when the vulnerable software handles a malicious VBScript code that tricks user to press F1 key. It allows a remote attacker to execute arbitrary command via sending a crafted web page.
Affected ProductsMicrosoft Internet Explorer 7 and 8 on Windows XP
Recommended ActionsInstall patches when available.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0483
Reference/shttp://isec.pl/vulnerabilities/isec-0027-msgbox-helpfile-ie.txt
http://secunia.com/advisories/38727/
http://www.exploit-db.com/exploits/11615
http://www.microsoft.com/technet/security/advisory/981169.mspx
http://www.vupen.com/english/advisories/2010/0485
Reference: VID-18252