4.6
CVSSv2

CVE-1999-0975

Published: 10/12/1999 Updated: 09/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 98

microsoft windows 95

microsoft windows nt 4.0

Exploits

source: wwwsecurityfocuscom/bid/868/info The help files for the Windows Help system (*cnt, *hlp) can be edited so that they run an arbitrary executable when selected by a user The executable will run at the privelege level of the user The *cnt files are like tables of contents that tell the help system what to open when each topic i ...