Unrated severityNVD Advisory· Published Jun 14, 2004· Updated Jun 16, 2026
CVE-2004-0199
CVE-2004-0199
Description
Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15cpe:2.3:o:microsoft:windows_2003_server:enterprise:*:64-bit:*:*:*:*:*+ 7 more
- cpe:2.3:o:microsoft:windows_2003_server:enterprise:*:64-bit:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_2003_server:r2:*:64-bit:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_2003_server:r2:*:datacenter_64-bit:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_2003_server:standard:*:64-bit:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_2003_server:web:*:*:*:*:*:*:*
- (no CPE)range: SP1
cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*+ 6 more
- cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_xp:*:gold:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_xp:*:sp1:64-bit:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
9- www.kb.cert.org/vuls/id/484814nvdPatchThird Party AdvisoryUS Government Resource
- www.securityfocus.com/bid/10321nvdExploitPatchVendor Advisory
- marc.infonvd
- marc.infonvd
- www.exploitlabs.com/files/advisories/EXPL-A-2004-001-helpctr.txtnvd
- docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-015nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/16095nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1008nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1032nvd
News mentions
0No linked articles in our index yet.