CVE-2004-1306
Windows NT, 2000, XP, 2003 - Remote Code Execution via Crafted .hlp File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1306. PoCs published by flashsky fangxing.
AI-analyzed exploit summary The provided text describes an integer overflow vulnerability in Microsoft Windows' winhlp32.exe when processing malformed compressed Windows Help files (.hlp). Successful exploitation could lead to arbitrary code execution in the context of the user opening the malicious file.
Description
Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a crafted .hlp file.
Exploits (1)
The provided text describes an integer overflow vulnerability in Microsoft Windows' winhlp32.exe when processing malformed compressed Windows Help files (.hlp). Successful exploitation could lead to arbitrary code execution in the context of the user opening the malicious file.