Windows XP Zero-Day Targeted by Hackers in Drive-by Attack

執筆者
Brian Prince
Brian Prince
Published: Jun 15, 2010
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Attackers have begun exploiting a zero-day vulnerability to target Windows XP machines. The vulnerability has given rise to renewed debate about responsible disclosure.

According to Sophos Senior Technology Consultant Graham Cluley, a legitimate Website pushing open-source software was seen serving the exploit to PC users. Cluley declined to name the site, but Microsoft confirmed that it was aware the bug was being exploited and said the exploits had been “taken down.”

An analysis of the exploits found that Windows Server 2003 systems are not being targeted, according to an updated advisory. However, the vulnerability lies within the Windows Help and Support Center function delivered in both XP and Windows Server 2003, meaning that Windows Server 2003 systems could eventually be targeted.

A successful exploit could allow an attacker to remotely execute code if the user views a specially crafted or compromised Web page like the ones found by Sophos.

“The malware that is downloaded is a very large Delphi-based Trojan, which includes an entire portable version of Firefox,” Cluley said. “It appears that they are trying to distribute this ‘customized’ version of Firefox to make money through clickable banner ads.”

The vulnerability was uncovered by Google engineer Tavis Ormandy, who published exploit code on the Full Disclosure mailing list five days after notifying Microsoft of his findings. Some have criticized Ormandy’s actions, saying he did not give Microsoft enough time to patch before going public with details of the attack. Ormandy defended himself in his Full Disclosure post on the grounds that had he gone public without a working exploit he “would have been ignored.”

Microsoft did not offer a definitive timeline for a patch, but told eWEEK a security update for the issue is forthcoming. In the meantime, the company has included information on a workaround in its advisory. Customers concerned about the exploit can disable the HCP protocol, which “will break all local, legitimate help links that use hcp://.”

A tool that can be used to disable the HCP protocol can be downloaded here.

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。