CVE-2010-1885 is a critical vulnerability affecting Microsoft Windows XP and Windows Server 2003, where the Help and Support Center's MPC::HexToNum function improperly handles malformed escape sequences in hcp:// URLs. This allows remote attackers to bypass security restrictions and execute arbitrary commands. With a CVSS score of 9.3, it presents a high-severity risk due to its network-based attack vector, medium complexity, and complete compromise of confidentiality, integrity, and availability. Although not listed on the KEV catalog, exploit modules are available in Metasploit and ExploitDB, indicating readily accessible exploitation tools, and it has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:*:sp2:itanium:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.