CVE-2007-0427
Microsoft HTML Help Workshop - Stack-based Buffer Overflow via Long HLP Field in OPTIONS Section
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-0427. PoCs published by porkythepig.
AI-analyzed exploit summary This is a functional exploit for CVE-2007-0427, targeting a buffer overflow vulnerability in Microsoft Help Workshop v4.03.0002. It crafts a malicious .HPJ project file that, when opened, executes arbitrary code via a carefully constructed payload with hardcoded API addresses for various Windows versions.
Description
Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section.
Exploits (2)
This is a functional exploit for CVE-2007-0427, targeting a buffer overflow vulnerability in Microsoft Help Workshop v4.03.0002. It crafts a malicious .HPJ project file that, when opened, executes arbitrary code via a carefully constructed payload with hardcoded API addresses for various Windows versions.
This is a functional exploit for CVE-2007-0352, targeting a buffer overflow vulnerability in Microsoft Help Workshop v4.03.0002. It generates a malicious .cnt file that triggers arbitrary code execution when opened, spawning a specified process (default: notepad.exe).