|
|
|
![]() |
Vulnerability Note VU#115632Microsoft Windows help viewer vulnerable to heap overflowOverviewA vulnerability exists in the Microsoft Windows help viewer application that could allow a remote attacker to execute code of their choosing on a vulnerable system.I. DescriptionThe Microsoft Windows help viewer (winhlp32.exe) provides application assistance to users through a special type of file (.hlp). The help file format allows for compression of frequently used phrases. When this feature is employed, information about phrases, including size and number, is stored in a table in the help file. An unsafe use of information supplied during decoding of the phrase table could result in an incorrect memory allocation. This error results in a heap memory overflow that can be exploited by a malformed help file that specifies an invalid size in the phrase table.Note that this vulnerability may only affect versions of Microsoft Windows with certain language packs installed. The full scope of affected systems is unclear at the current time.
References
Thanks to flashsky fangxing for reporting this vulnerability. This document was written by Ken MacInnis.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||