CVE-2004-1043

EXPLOITED

Internet Explorer 6.0 on Windows XP SP2 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2004-1043 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Paul.

AI-analyzed exploit summary This exploit leverages a vulnerability in the HTML Help ActiveX control (hhctrl.ocx) to execute arbitrary code via a crafted HTML file. It uses JavaScript and VBScript to download and execute a malicious payload, achieving remote code execution (RCE) on vulnerable systems.

Description

Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, which saves a .HTA file to the local system, aka the "HTML Help ActiveX control Cross Domain Vulnerability."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Paul · textremotewindows
https://www.exploit-db.com/exploits/719

This exploit leverages a vulnerability in the HTML Help ActiveX control (hhctrl.ocx) to execute arbitrary code via a crafted HTML file. It uses JavaScript and VBScript to download and execute a malicious payload, achieving remote code execution (RCE) on vulnerable systems.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft HTML Help Control (hhctrl.ocx) versions prior to 5.2.3790.1194
No auth needed
Prerequisites: Victim must open the malicious HTML file · Vulnerable version of hhctrl.ocx must be installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1349
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1963
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/972415
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18311
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2004-12/0426.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2830
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA05-012B.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3496

Scores

EPSS 0.7450
EPSS Percentile 98.9%

Details

VulnCheck KEV 2005-01-11
Status published
Products (2)
microsoft/internet_explorer 6.0
microsoft/windows_xp
Published Dec 31, 2004
Tracked Since Feb 18, 2026