20021003 Buffer Overflow in IE/Outlook HTML Helpmailing list
http://marc.info/?l=bugtraq&m=103365849505409&w=2 CVE-2002-0693
Microsoft Windows XP/2000/NT 4.0 - Help Facility ActiveX Control Buffer Overflow
Record summary
CVE-2002-0693 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Windows XP/2000/NT 4.0 - Help Facility ActiveX Control Buffer OverflowExploitDB exploitby ipxodiNot analyzed1 file
References
820021009 Thor Larholm security advisory TL#004mailing list
http://marc.info/?l=bugtraq&m=103419115517344&w=2 20021010 prover of concept code of windows help overflowmailing list
http://marc.info/?l=bugtraq&m=103435279404182&w=2 win-html-help-bo(10253)vdb entry
http://www.iss.net/security_center/static/10253.php 5874vdb entry
http://www.securityfocus.com/bid/5874 MS02-055Vendor advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-055 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0693 oval:org.mitre.oval:def:374vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A374