Short Name |
HTTP:STC:CLSID:ACTIVEX:WH32-OF
|
Severity |
Medium
|
Recommended |
No
|
Category |
HTTP
|
Keywords |
WinHelp32.exe Remote Buffer Overrun
|
Release Date |
2003/04/22
|
Update Number |
1213
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+
|
HTTP: WinHelp32.exe Remote Buffer Overrun
This signature detects attempts to exploit a known vulnerability against Microsoft HTML Help, which provides functionality for Windows help systems. Help ActiveX control (Hhctrl.ocx) is used by winhelp32.exe. Winhlp performs insufficient bounds checking of the Item parameter in the WinHlp command. Attackers can embed a call to the vulnerable ActiveX control in a malicious Web page or HTML e-mail to execute arbitrary commands as the Internet Explorer user.
Extended Description
HTML Help ActiveX control (Hhctrl.ocx) ships as part of Microsoft HTML Help and is designed to work with Internet Explorer to provide functionality for help systems.
A remotely exploitable issue has been reported in the WinHlp facility. The software fails to perform sufficient boundary checks of the Item parameter in the WinHlp command. This issue resides in Winhlp32.exe.
An attacker can exploit this condition by embedding a call to the vulnerable ActiveX control in a malicious webpage or HTML email. If successful, the attacker may be able to execute arbitrary code on the client system as the Internet Explorer user.
Note that Windows ships with HTML Help.
The HTML Help ActiveX control can also reportedly be used to mount denial-of-service attacks and exploit other stack- and heap-based overflows.
Tiny Personal Firewall 3.0 reportedly treats the HTML Help facility as a trusted application in the default configuration. As a result, any outgoing/back-channel connections that stem from successful exploits will not be blocked by the firewall in the default configuration. Note that this issue is reportedly not present in Tiny Personal Firewall 2.0.
Affected Products
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server SP1
- Microsoft Windows 2000 Datacenter Server SP2
- Microsoft Windows 2000 Datacenter Server
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Terminal Services SP1
- Microsoft Windows 2000 Terminal Services SP2
- Microsoft Windows 2000 Terminal Services
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows ME
- Microsoft Windows NT Enterprise Server 4.0
- Microsoft Windows NT Enterprise Server 4.0 SP1
- Microsoft Windows NT Enterprise Server 4.0 SP2
- Microsoft Windows NT Enterprise Server 4.0 SP3
- Microsoft Windows NT Enterprise Server 4.0 SP4
- Microsoft Windows NT Enterprise Server 4.0 SP5
- Microsoft Windows NT Enterprise Server 4.0 SP6
- Microsoft Windows NT Enterprise Server 4.0 SP6a
- Microsoft Windows NT Server 4.0
- Microsoft Windows NT Server 4.0 SP1
- Microsoft Windows NT Server 4.0 SP2
- Microsoft Windows NT Server 4.0 SP3
- Microsoft Windows NT Server 4.0 SP4
- Microsoft Windows NT Server 4.0 SP5
- Microsoft Windows NT Server 4.0 SP6
- Microsoft Windows NT Server 4.0 SP6a
- Microsoft Windows NT Terminal Server 4.0
- Microsoft Windows NT Terminal Server 4.0 SP1
- Microsoft Windows NT Terminal Server 4.0 SP2
- Microsoft Windows NT Terminal Server 4.0 SP3
- Microsoft Windows NT Terminal Server 4.0 SP4
- Microsoft Windows NT Terminal Server 4.0 SP5
- Microsoft Windows NT Terminal Server 4.0 SP6
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows XP Home
- Microsoft Windows XP Professional
References