Microsoft Help File Trojan Vulnerability
BID:868
Info
Microsoft Help File Trojan Vulnerability
| Bugtraq ID: | 868 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 10 1999 12:00AM |
| Updated: | Dec 10 1999 12:00AM |
| Credit: | Posted to Bugtraq by Pauli Ojanpera <[email protected]> on December 7, 1999. |
| Vulnerable: |
Microsoft Windows NT 4.0 Microsoft Windows 98 Microsoft Windows 95 |
| Not Vulnerable: | |
Discussion
Microsoft Help File Trojan Vulnerability
The help files for the Windows Help system (*.cnt, *.hlp) can be edited so that they run an arbitrary executable when selected by a user. The executable will run at the privelege level of the user.
The *.cnt files are like tables of contents that tell the help system what to open when each topic is selected. These entries can be edited to cause system and DLL calls and programs to be executed when a topic is chosen. The help files themselves, *.hlp, can be edited in a similar manner.
The help files for the Windows Help system (*.cnt, *.hlp) can be edited so that they run an arbitrary executable when selected by a user. The executable will run at the privelege level of the user.
The *.cnt files are like tables of contents that tell the help system what to open when each topic is selected. These entries can be edited to cause system and DLL calls and programs to be executed when a topic is chosen. The help files themselves, *.hlp, can be edited in a similar manner.
Solution / Fix
Microsoft Help File Trojan Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Microsoft Help File Trojan Vulnerability
References:
References: