A researcher has discovered a flaw residing in the Windows Help and Support Center, a feature that provides users with online technical support. Malicious hackers can easily exploit the weakness of Windows by embedding commands in web addresses that activate the feature s remote assistance tool, which allows administrators to execute commands over the internet. A critical path-traversal flaw (CVE-2020-27130) exists in Cisco Security Manager that lays bare sensitive information to remote, unauthenticated attackers. Read the full advisory.
Source: https://threatpost.com/ms-xp-server-2003-flaw-allows-remote-pc-control-061010/74090/

