A malicious Win-XP Help Center request can easily and silently delete the contents of any directory on your Windows machine.
http://www.theregister.co.uk/content/4/27074.html
Printable View
A malicious Win-XP Help Center request can easily and silently delete the contents of any directory on your Windows machine.
http://www.theregister.co.uk/content/4/27074.html
big security problem, but was fixed in SP1
Microsoft should be making it front page news so people can fix it even if they don't install SP1.
For those on dialup that have not yet been able to apply SP1 yet, patch courtesy of Steve Gibson here
If you don't want to use Gibsons software, you can apply the fix yourself in just a few seconds.
Just simply paste this into your browser and hit enter:
C:\Windows\PCHEALTH\HELPCTR\SYSTEM\DFS\
Note: Use the correct drive letter for your particular setup.
Locate the file called uplddrvinfo.htm. and simply either delete it or rename it.
Problem solved.