5.1
CVSSv2

CVE-2004-1306

Published: 31/12/2004 Updated: 30/04/2019
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote malicious users to execute arbitrary code via a crafted .hlp file.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 2003 server r2

microsoft windows nt 4.0

microsoft windows xp

microsoft windows 2000

microsoft windows 2003 server enterprise_64-bit

microsoft windows 2003 server enterprise

microsoft windows 2003 server web

microsoft windows 2003 server datacenter_64-bit

microsoft windows 2003 server standard

Exploits

source: wwwsecurityfocuscom/bid/12091/info Microsoft Windows is prone to an integer overflow vulnerability This issue exists in 'winhlp32exe' and is exposed when a malformed phrase compressed Windows Help file (hlp) is processed by the program Successful exploitation may allow execution of arbitrary code in the context of the user th ...