Last week, Microsoft released Security Advisory 2219475, addressing a vulnerability in the Windows Help and Support Center function in Windows XP and Windows Server 2003. Microsoft updated the Executive Summary of the Security Advisory after becoming aware of limited, targeted active attacks that use the published proof-of-concept exploit code. Note that based on the samples analyzed, Windows Server 2003 systems are not currently at risk from the attacks.
Fix it
For anyone using an operating system affected by the Windows Help and Support Center vulnerability, Microsoft released KB Article 2219475, "Vulnerability in Help Center could allow remote code execution". The KB Article which includes a Fix it solution to protect computers from the vulnerability. Also included is an "undo" Fix it to reverse the process after a security update has been released addressing the issue.
Click the Fix it image above or go to Microsoft Fix it to download the wizard to fix this problem automatically.
Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Vulnerabilities, Information,
If you are in a enterprise environment you may also want to check out a blog post i wrote with instructions on how to do this via Group Policy at http://www.grouppolicy.biz/2010/06/how-to-mitigate-windows-help-security-issue-kb2219475-with-group-policy/
ReplyDeleteAlan Burchill (MVP)
NICE QUOTE!
ReplyDelete