CVE-2002-0693

Windows HTML Help ActiveX Control Buffer Overflow RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0693. PoCs published by ipxodi.

AI-analyzed exploit summary This exploit targets a buffer overflow in the Windows Help Center ActiveX control (CVE-2002-0693) to achieve remote code execution. It generates an HTML file that triggers the vulnerability when opened in Internet Explorer, spawning a command shell.

Description

Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ipxodi · cremotewindows
https://www.exploit-db.com/exploits/21902

This exploit targets a buffer overflow in the Windows Help Center ActiveX control (CVE-2002-0693) to achieve remote code execution. It generates an HTML file that triggers the vulnerability when opened in Internet Explorer, spawning a command shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Windows Help Center ActiveX control (IE 5.5, 5.5 SP2, 6.0)
No auth needed
Prerequisites: Victim must open the generated HTML file in a vulnerable version of Internet Explorer
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A374
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5874
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103365849505409&w=2
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103435279404182&w=2
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10253.php
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103419115517344&w=2

Scores

EPSS 0.5242
EPSS Percentile 98.8%

Details

Status published
Products (7)
microsoft/windows_2000 (4 CPE variants)
microsoft/windows_2000_terminal_services (4 CPE variants)
microsoft/windows_98
microsoft/windows_98se
microsoft/windows_me
microsoft/windows_nt 4.0 (32 CPE variants)
microsoft/windows_xp (3 CPE variants)
Published Oct 10, 2002
Tracked Since Feb 18, 2026