Skip to main content

Microsoft to XP Users: Don’t Press F1

Image used with permission by copyright holder

On the heels of a Google engineer finding a security vulnerability that had been lurking in Microsoft Windows’ Virtual DOS Machine for 17 years, another doozy has turned up: Microsoft has issued a security advisory for Windows 2000, Windows XP, and Windows Server 2003 that just pressing the F1 key—you know, for help—while using Internet Explorer could trigger a VBScript vulnerability that could enable attackers to take over the machine.

“The vulnerability exists in the way that VBScript interacts with Windows Help files when using Internet Explorer,” Microsoft wrote in the advisory. “If a malicious Web site displayed a specially crafted dialog box and a user pressed the F1 key, arbitrary code could be executed in the security context of the currently logged-on user.”

In theory, the flaw could be exploited by attackers passing malware disguised as a Windows Help (“.hlp“) file. Exploiting the issue does require that the attackers somehow convince users to press the F1 key to trigger the vulnerability. The flaw impacts Internet Explorer 6, 7, and 8 on the affected operating systems; Windows Vista and Windows 7 are not vulnerable.

“As an interim workaround, users are advised to avoid pressing F1 on dialogs presented from Web pages or other Internet content,” said Microsoft Security Response Center’s David Ross, in a Technet blog post.

Microsoft has expressed dismay that the vulnerability was made public before a patch could be developed and deployed to mitigate the risk. Typically, security researchers report flaws to vendors privately so a workaround can be tested and released before announcing the flaw to the broader world where attackers and cybercriminals might move quickly to exploit it.

Editors' Recommendations

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Apple Mac Mini M2 vs. M1: don’t make a buying mistake
Apple Mac Mini M1 sitting on a desk.

Apple's new Mac Mini M2 promises better performance and features at a lower price. But with the next-gen machine now out and making the rounds, you can score a deal on a last-gen Mac Mini M1. Which should you buy?

With the same external design and similar port selection, the Mac Mini M2 looks like an internal-only upgrade to Apple's mini desktop. There are some significant differences compared to the M1 model, however, and they can make a huge difference in performance.
Pricing

Read more
Microsoft’s DirectStorage may improve loading times by 200%, but don’t get too excited
Person using a gaming monitor.

Microsoft has just introduced GPU decompression to its new DirectStorage API, bringing it to version 1.1.

GPU decompression can provide huge performance gains in gaming -- Microsoft promises up to a 200% performance improvement in loading times. Unfortunately, it's still much too early to get excited -- we might not see DirectStorage for quite a while.

Read more
Don’t fall for this devious new Microsoft Office scam
A package with a fake Microsoft Office USB stick.

With packaging looking legitimate enough at first glance, scammers are sending out fake Microsoft Office USB sticks -- loaded with ransomware -- to individuals.

As reported by Tom’s Hardware and PCMag, the USBs are sent out to randomly selected addresses in the hopes of convincing targets that they inadvertently received a $439 Office Professional Plus package.

Read more