Skip to main content

Microsoft to XP Users: Don’t Press F1

Image used with permission by copyright holder

On the heels of a Google engineer finding a security vulnerability that had been lurking in Microsoft Windows’ Virtual DOS Machine for 17 years, another doozy has turned up: Microsoft has issued a security advisory for Windows 2000, Windows XP, and Windows Server 2003 that just pressing the F1 key—you know, for help—while using Internet Explorer could trigger a VBScript vulnerability that could enable attackers to take over the machine.

“The vulnerability exists in the way that VBScript interacts with Windows Help files when using Internet Explorer,” Microsoft wrote in the advisory. “If a malicious Web site displayed a specially crafted dialog box and a user pressed the F1 key, arbitrary code could be executed in the security context of the currently logged-on user.”

Recommended Videos

In theory, the flaw could be exploited by attackers passing malware disguised as a Windows Help (“.hlp“) file. Exploiting the issue does require that the attackers somehow convince users to press the F1 key to trigger the vulnerability. The flaw impacts Internet Explorer 6, 7, and 8 on the affected operating systems; Windows Vista and Windows 7 are not vulnerable.

“As an interim workaround, users are advised to avoid pressing F1 on dialogs presented from Web pages or other Internet content,” said Microsoft Security Response Center’s David Ross, in a Technet blog post.

Microsoft has expressed dismay that the vulnerability was made public before a patch could be developed and deployed to mitigate the risk. Typically, security researchers report flaws to vendors privately so a workaround can be tested and released before announcing the flaw to the broader world where attackers and cybercriminals might move quickly to exploit it.

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
If you use a VPN, don’t skip this important Windows 11 update
Microsoft Surface Laptop Go 3 rear view showing lid and logo.

It's not you; Windows is causing the issues this time. If the VPN on your Windows 11 or Windows 10 computer is having a hard time connecting, it is likely because of Microsoft's April security updates for Windows 11 (KB5036893 for) and Windows 10 (KB5036892), which have been reported to be the cause of the problems.

But there's good news. According to Microsoft, a patch is now available to fix the VPN problems users are experiencing.

Read more
Whatever you do, don’t buy a Windows laptop right now
Gaming on a laptop with the Snapdragon X Elite chip

There's a revolution in the making. Those of us who've been watching closely know that Qualcomm's Snapdragon X Elite chips are rumored to be just around the corner. And they're about to ignite a bomb in the world of Windows laptops.

That might sound like exaggeration at first blush. But Qualcomm has spent the better part of this year trotting around a demo unit with this chip, and the performance so far looks pretty astounding. Not only is Qualcomm claiming that its new chips will run circles around Intel's latest Core Ultra chips -- but it's even pitting them against Apple's M3. That's right. There's even a significant jump in AI performance via the chip's neural processing unit (NPU).

Read more
Microsoft plans to charge for Windows 10 updates in the future
Windows 11 and Windows 10 operating system logos are displayed on laptop screens.

Microsoft has confirmed it will offer security updates for Windows 10 after the end-of-life date for the operating system for consumer users but for a fee.

The brand recently announced plans to charge regular users for Extended Security Updates (ESU) who intend to continue using Windows 10 beyond the October 14, 2025 support date.

Read more