CVE-2002-0823
Windows Help - Remote Code Execution via HTML Help ActiveX Control Item Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-0823. PoCs published by Next Generation Security.
AI-analyzed exploit summary This exploit leverages a buffer overflow in the HTML Help ActiveX control (Hhctrl.ocx) via the WinHlp command's Item parameter. The malicious OBJECT tag and embedded script trigger arbitrary code execution when rendered in Internet Explorer.
Description
Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HTML Help ActiveX control (HHCtrl.ocx) with a long pathname in the Item parameter.
Exploits (1)
This exploit leverages a buffer overflow in the HTML Help ActiveX control (Hhctrl.ocx) via the WinHlp command's Item parameter. The malicious OBJECT tag and embedded script trigger arbitrary code execution when rendered in Internet Explorer.