Microsoft Windows Help Facilities Vulnerabilities
BID:5872
Info
Microsoft Windows Help Facilities Vulnerabilities
| Bugtraq ID: | 5872 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2002 12:00AM |
| Updated: | Oct 03 2002 12:00AM |
| Credit: | Discovery is credited to David Litchfield of Next Generation Security Software Ltd. and Thor Larholm of PivX Solutions. |
| Vulnerable: |
Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows ME Microsoft Windows 98SE Microsoft Windows 98 SP1 Microsoft Windows 98 j Microsoft Windows 98 b Microsoft Windows 98 a Microsoft Windows 98 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows Help Facilities Vulnerabilities
Microsoft has reported two vulnerabilities in its Windows Help Facilities.
The first vulnerability is in a function exposed in an ActiveX control. Attackers may invoke and exploit the control through a malicious webpage or HTML email. The vulnerability is a buffer overflow condition and may be levaraged by attackers to execute arbitrary code on victim systems. Any code executed would run in the security context of Explorer.
The second vulnerability involves Compiled Help Files (chm) and may allow for attackers to execute commands on the victim host. The Help Facilities component will execute potentially malicious .chm files in the Temporary Internet Files folder. This behaviour has been corrected in a patch developed by Microsoft.
**Note: This database entry is temporary. New vulnerabilities are to be given unique Bugtraq IDs and alerts will be published for each individual issue. This BID will be retired when analysis is complete.
Microsoft has reported two vulnerabilities in its Windows Help Facilities.
The first vulnerability is in a function exposed in an ActiveX control. Attackers may invoke and exploit the control through a malicious webpage or HTML email. The vulnerability is a buffer overflow condition and may be levaraged by attackers to execute arbitrary code on victim systems. Any code executed would run in the security context of Explorer.
The second vulnerability involves Compiled Help Files (chm) and may allow for attackers to execute commands on the victim host. The Help Facilities component will execute potentially malicious .chm files in the Temporary Internet Files folder. This behaviour has been corrected in a patch developed by Microsoft.
**Note: This database entry is temporary. New vulnerabilities are to be given unique Bugtraq IDs and alerts will be published for each individual issue. This BID will be retired when analysis is complete.
Exploit / POC
Microsoft Windows Help Facilities Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Windows Help Facilities Vulnerabilities
Solution:
Windows ME fixes may only be obtained through Windows Update.
Patches are available:
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Advanced Server SP1
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows NT Workstation 4.0 SP6a
Microsoft Windows 2000 Professional SP3
Microsoft Windows 98SE
Microsoft Windows NT Server 4.0 SP6a
Microsoft Windows 2000 Professional SP2
Microsoft Windows 2000 Professional
Microsoft Windows 98
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows XP Home SP1
Microsoft Windows 2000 Professional SP1
Microsoft Windows 2000 Server SP3
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows 2000 Server SP1
Microsoft Windows XP Professional SP1
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Server
Solution:
Windows ME fixes may only be obtained through Windows Update.
Patches are available:
Microsoft Windows 2000 Server SP2
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=40213
Microsoft Windows 2000 Advanced Server SP1
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=40213
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=40213
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43308
Microsoft Windows 2000 Professional SP3
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=40213
Microsoft Windows 98SE
-
Microsoft Q323255
http://www.microsoft.com/windows98/downloads/contents/WUCritical/q3232 55/default.asp
Microsoft Windows NT Server 4.0 SP6a
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43308
Microsoft Windows 2000 Professional SP2
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=40213
Microsoft Windows 2000 Professional
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=40213
Microsoft Windows 98
-
Microsoft Q323255
http://www.microsoft.com/windows98/downloads/contents/WUCritical/q3232 55/default.asp
Microsoft Windows 2000 Advanced Server SP3
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=40213
Microsoft Windows XP Home SP1
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=41834
Microsoft Windows 2000 Professional SP1
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=40213
Microsoft Windows 2000 Server SP3
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=40213
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43308
Microsoft Windows 2000 Server SP1
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=40213
Microsoft Windows XP Professional SP1
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=41834
Microsoft Windows 2000 Advanced Server
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=40213
Microsoft Windows 2000 Server
-
Microsoft Q323255
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=40213
References
Microsoft Windows Help Facilities Vulnerabilities
References:
References:
- Microsoft Security Bulletin MS02-055 (Microsoft)