vendor:
HTML Help Workshop
by:
bratax
9
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: HTML Help Workshop
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP
Microsoft HTML Help Workshop .hhp file Buffer Overflow Exploit
This exploit targets a buffer overflow vulnerability in Microsoft HTML Help Workshop. By creating a specially crafted .hhp file, an attacker can trigger a buffer overflow and execute arbitrary code on the target system. The exploit code includes a bindshell payload that opens a listening port (13579) on the target machine. This exploit is based on code from realplayer .smil exploit.
Mitigation:
Apply the latest security patches and updates from Microsoft to prevent this vulnerability. Avoid opening or running untrusted .hhp files.