Back

CVE-2003-0009

Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.

Published: Mar 7, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
microsoft windows_me *
microsoft windows_xp *
microsoft windows_xp *

GitHub Security Advisory GHSA-38g3-w7mj-hw2f

Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me...

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 16.48%

Top 3% most likely to be exploited

Threat Score 32.1 / 100

Data Sources

NVD EPSS GitHub