vendor:
HTML Help Workshop
by:
Dz_attacker
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: HTML Help Workshop
Affected Version From: 4.74
Affected Version To: 4.74
Patch Exists: YES
Related CWE: CVE-2009-2521
CPE: a:microsoft:html_help_workshop:4.74
Other Scripts:
https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/dos/windows/ftp/iis_list_exhaustion, https://www.infosecmatter.com/nessus-plugin-library/?id=79507, https://www.infosecmatter.com/nessus-plugin-library/?id=89674, https://www.infosecmatter.com/nessus-plugin-library/?id=51971, https://www.infosecmatter.com/nessus-plugin-library/?id=48387, https://www.infosecmatter.com/nessus-plugin-library/?id=50044, https://www.infosecmatter.com/nessus-plugin-library/?id=109432, https://www.infosecmatter.com/metasploit-auxiliary-modules-detailed-spreadsheet/
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3, SP2, Windows 2000
2009
HTML Help Workshop 4.74 (hhp) Buffer Overflow Exploit (Universal)
A buffer overflow vulnerability exists in HTML Help Workshop 4.74, which could allow remote code execution. The vulnerability is due to a boundary error when handling a specially crafted .hhp file. An attacker could exploit this vulnerability by enticing a user to open a malicious .hhp file. Successful exploitation could result in arbitrary code execution in the context of the user.
Mitigation:
Upgrade to the latest version of HTML Help Workshop 4.74 or later.