CVE-2004-0201
CVSS10.0
发布时间 :2004-08-06 00:00:00
修订时间 :2008-09-10 15:25:29
NMCOPS    

[原文]Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.


[CNNVD]Microsoft HTML Help任意代码执行漏洞(MS04-023)(CNNVD-200408-027)

        
        Microsoft Windows允许应用程序使用一种标准方法显示和处理帮助文件。其中之一的方法是使用HTML帮助API。
        Microsoft Windows HTML Help存在问题,远程攻击者可以利用这个漏洞以用户进程权限在系统上执行任意代码。
        攻击者构建恶意页面,诱使用户访问,可以目标用户进程权限执行任意代码,包括安装程序,查看更改删除数据,建立新帐户等攻击。目前没有详细漏洞细节。
        另外一个问题是特殊构建的showHelp URL可导致远程任意代码在本地电脑区域中执行。
        

- CVSS (基础分值)

CVSS分值: 10 [严重(HIGH)]
机密性影响: COMPLETE [完全的信息泄露导致所有系统文件暴露]
完整性影响: COMPLETE [系统完整性可被完全破坏]
可用性影响: COMPLETE [可能导致系统完全宕机]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: [--]
身份认证: NONE [漏洞利用无需身份认证]

- CPE (受影响的平台与产品)

cpe:/o:microsoft:windows_nt:4.0:sp1:serverMicrosoft Windows 4.0 sp1 server
cpe:/o:microsoft:windows_meMicrosoft Windows ME
cpe:/o:microsoft:windows_98::goldMicrosoft windows 98_gold
cpe:/o:microsoft:windows_2000::sp1:datacenter_serverMicrosoft Windows 2000 Datacenter Server SP1
cpe:/o:microsoft:windows_nt:4.0::server
cpe:/o:microsoft:windows_nt:4.0:sp5:workstationMicrosoft Windows 4.0 sp5 workstation
cpe:/o:microsoft:windows_nt:4.0:sp3:workstationMicrosoft Windows 4.0 sp3 workstation
cpe:/o:microsoft:windows_xp::gold:professionalMicrosoft Windows XP Professional Gold
cpe:/o:microsoft:windows_2003_server:r2::datacenter_64-bit
cpe:/o:microsoft:windows_nt:4.0::enterprise_server
cpe:/o:microsoft:windows_2000::sp2:advanced_serverMicrosoft Windows 2000 Advanced Server SP2
cpe:/o:microsoft:windows_2000::sp2:professionalMicrosoft Windows 2000 Professional SP2
cpe:/o:microsoft:windows_2003_server:enterprise::64-bit
cpe:/o:microsoft:windows_nt:4.0:sp1:workstationMicrosoft Windows 4.0 sp1 workstation
cpe:/o:microsoft:windows_nt:4.0:sp4:workstationMicrosoft Windows 4.0 sp4 workstation
cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server
cpe:/o:microsoft:windows_2000:::professional
cpe:/o:microsoft:windows_xp::sp1:home
cpe:/o:microsoft:windows_nt:4.0:sp6a:serverMicrosoft Windows 4.0 sp6a server
cpe:/o:microsoft:windows_2003_server:standard::64-bit
cpe:/o:microsoft:windows_2003_server:enterprise_64-bit
cpe:/o:microsoft:windows_98seMicrosoft windows 98_se
cpe:/o:microsoft:windows_2000::sp1:professionalMicrosoft Windows 2000 Professional SP1
cpe:/o:microsoft:windows_nt:4.0:sp6:terminal_serverMicrosoft Windows NT Terminal Server 4.0 SP6
cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server
cpe:/o:microsoft:windows_xp:::home
cpe:/h:avaya:definity_one_media_serverAvaya DefinityOne Media Server
cpe:/o:microsoft:windows_nt:4.0:sp2:serverMicrosoft Windows 4.0 sp2 server
cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server
cpe:/o:microsoft:windows_nt:4.0:sp3:serverMicrosoft Windows 4.0 sp3 server
cpe:/o:microsoft:windows_xp:::64-bit
cpe:/o:microsoft:windows_nt:4.0:sp4:terminal_serverMicrosoft Windows NT Terminal Server 4.0 SP4
cpe:/o:microsoft:windows_2000::sp2:datacenter_serverMicrosoft Windows 2000 Datacenter Server SP2
cpe:/o:microsoft:windows_2000::sp4:datacenter_serverMicrosoft Windows 2000 Datacenter Server SP4
cpe:/a:avaya:ip600_media_serversAvaya IP600 Media Servers
cpe:/o:microsoft:windows_2000:::server
cpe:/o:microsoft:windows_nt:4.0:sp6:serverMicrosoft Windows 4.0 sp6 server
cpe:/o:microsoft:windows_nt:4.0:sp1:terminal_serverMicrosoft Windows NT Terminal Server 4.0 SP1
cpe:/o:microsoft:windows_nt:4.0:sp3:terminal_serverMicrosoft Windows NT Terminal Server 4.0 SP3
cpe:/o:microsoft:windows_nt:4.0:sp4:serverMicrosoft Windows 4.0 sp4 server
cpe:/o:microsoft:windows_nt:4.0::terminal_server
cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server
cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server
cpe:/o:microsoft:windows_2003_server:r2::64-bit
cpe:/o:microsoft:windows_2000::sp3:datacenter_serverMicrosoft Windows 2000 Datacenter Server SP3
cpe:/o:microsoft:windows_nt:4.0:sp6a:workstationMicrosoft Windows 4.0 sp6a workstation
cpe:/o:microsoft:windows_nt:4.0:sp6:enterprise_server
cpe:/o:microsoft:windows_2000::sp3:serverMicrosoft Windows 2000 Server SP3
cpe:/o:microsoft:windows_2000:::advanced_server
cpe:/o:microsoft:windows_nt:4.0:sp2:workstationMicrosoft Windows 4.0 sp2 workstation
cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server
cpe:/o:microsoft:windows_xp::sp1:64-bit
cpe:/o:microsoft:windows_2000::sp4:serverMicrosoft Windows 2000 Server SP4
cpe:/o:microsoft:windows_2000:::datacenter_server
cpe:/o:microsoft:windows_2000::sp3:professionalMicrosoft Windows 2000 Professional SP3
cpe:/o:microsoft:windows_2000::sp1:serverMicrosoft Windows 2000 Server SP1
cpe:/o:microsoft:windows_2000::sp3:advanced_serverMicrosoft Windows 2000 Advanced Server SP3
cpe:/o:microsoft:windows_2003_server:web
cpe:/o:microsoft:windows_nt:4.0:sp5:serverMicrosoft Windows 4.0 sp5 server
cpe:/o:microsoft:windows_2000::sp1:advanced_serverMicrosoft Windows 2000 Advanced Server SP1
cpe:/h:avaya:s8100Avaya S8100
cpe:/o:microsoft:windows_nt:4.0::workstation
cpe:/o:avaya:modular_messaging_message_storage_server:s3400
cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_serverMicrosoft Windows NT Terminal Server 4.0 SP5
cpe:/o:microsoft:windows_2000::sp2:serverMicrosoft Windows 2000 Server SP2
cpe:/o:microsoft:windows_nt:4.0:sp6:workstationMicrosoft Windows 4.0 sp6 workstation
cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_serverMicrosoft Windows NT Terminal Server 4.0 SP2
cpe:/o:microsoft:windows_2000::sp4:professionalMicrosoft Windows 2000 Professional SP4
cpe:/o:microsoft:windows_2000::sp4:advanced_serverMicrosoft Windows 2000 Advanced Server SP4

- OVAL (用于检测的技术细节)

oval:org.mitre.oval:def:3179Windows NT HtmlHelp Heap Overflow
oval:org.mitre.oval:def:2155Windows Server 2003 HtmlHelp Heap Overflow
oval:org.mitre.oval:def:1530Windows XP HtmlHelp Heap Overflow
oval:org.mitre.oval:def:1503Windows 2000 HtmlHelp Heap Overflow
*OVAL详细的描述了检测该漏洞的方法,你可以从相关的OVAL定义中找到更多检测该漏洞的技术细节。

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0201
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2004-0201
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200408-027
(官方数据源) CNNVD

- 其它链接及资源

http://www.us-cert.gov/cas/techalerts/TA04-196A.html
(VENDOR_ADVISORY)  CERT  TA04-196A
http://www.kb.cert.org/vuls/id/920060
(VENDOR_ADVISORY)  CERT-VN  VU#920060
http://www.microsoft.com/technet/security/bulletin/MS04-023.mspx
(VENDOR_ADVISORY)  MS  MS04-023
http://xforce.iss.net/xforce/xfdb/16586
(VENDOR_ADVISORY)  XF  win-htmlhelp-execute-code(16586)
http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023919.html
(UNKNOWN)  FULLDISC  20040714 HtmlHelp - .CHM File Heap Overflow

- 漏洞信息

Microsoft HTML Help任意代码执行漏洞(MS04-023)
危急 边界条件错误
2004-08-06 00:00:00 2005-10-28 00:00:00
远程  
        
        Microsoft Windows允许应用程序使用一种标准方法显示和处理帮助文件。其中之一的方法是使用HTML帮助API。
        Microsoft Windows HTML Help存在问题,远程攻击者可以利用这个漏洞以用户进程权限在系统上执行任意代码。
        攻击者构建恶意页面,诱使用户访问,可以目标用户进程权限执行任意代码,包括安装程序,查看更改删除数据,建立新帐户等攻击。目前没有详细漏洞细节。
        另外一个问题是特殊构建的showHelp URL可导致远程任意代码在本地电脑区域中执行。
        

- 公告与补丁

        临时解决方法:
        如果您不能立刻安装补丁或者升级,CNNVD建议您采取以下措施以降低威胁:
        * 反注册HTML Help协议:
        点击开始,运行"regsvr32 /u %windir%\system32\itss.dll" ,在Win98系列中使用"system"代替"system32"。
        厂商补丁:
        Microsoft
        ---------
        Microsoft已经为此发布了一个安全公告(MS04-023)以及相应补丁:
        MS04-023:Vulnerability in HTML Help Could Allow Code Execution (840315)
        链接:
        http://www.microsoft.com/technet/security/bulletin/MS04-023.mspx

        补丁下载:
        Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft Windows 2000 Service Pack 4:
        
        http://www.microsoft.com/downloads/details.aspx?FamilyId=3F2F1A7D-5CF2-4791-A7EE-07F20F75796C&displaylang=en

        Microsoft Windows XP and Microsoft Windows XP Service Pack 1
        
        http://www.microsoft.com/downloads/details.aspx?FamilyId=8B412C7F-44AD-4E77-8973-FD3E84CC496A&displaylang=en

        Microsoft Windows XP 64-Bit Edition Service Pack 1
        
        http://www.microsoft.com/downloads/details.aspx?FamilyId=0042DB67-C58B-412C-A24F-9D2AA8071897&displaylang=en

        Microsoft Windows XP 64-Bit Edition Version 2003
        
        http://www.microsoft.com/downloads/details.aspx?FamilyId=DF0C5C4E-D986-4AD5-95E0-E87106D7C019&displaylang=en

        Microsoft Windows Server? 2003
        
        http://www.microsoft.com/downloads/details.aspx?FamilyId=8B53C35D-E9ED-46AD-936C-30C8E3A7E606&displaylang=en

        Microsoft Windows Server 2003 64-Bit Edition
        
        http://www.microsoft.com/downloads/details.aspx?FamilyId=DF0C5C4E-D986-4AD5-95E0-E87106D7C019&displaylang=en

- 漏洞信息 (F33788)

HtmlHelpchm.txt (PacketStormID:F33788)
2004-07-14 00:00:00
Brett Moore SA  security-assessment.com
advisory
windows,2k,9x,nt,xp
CVE-2004-0201
[点击下载]

The HtmlHelp application (hh.exe) in Microsoft windows read a value from a .CHM file to set a length parameter. By setting this to a large value, it is possible to overwrite sections of the heap with attacker supplied values. Affected software includes: Microsoft Windows 98, 98SE, ME, Microsoft Windows NT 4.0, Microsoft Windows 2000 Service Pack 4, Microsoft Windows XP, Microsoft Windows XP Service Pack 1, Microsoft Windows Server 2003.

========================================================================
= HtmlHelp - .CHM File Heap Overflow
=
= MS Bulletin posted: 
= http://www.microsoft.com/technet/security/bulletin/MS04-023.mspx
=
= Affected Software:
=	Microsoft Windows 98, 98SE, ME
=	Microsoft Windows NT 4.0
=	Microsoft Windows 2000 Service Pack 4
=	Microsoft Windows XP, Microsoft Windows XP Service Pack 1 
=	Microsoft Windows Server 2003 
=
= Public disclosure on July 14, 2004
========================================================================

When thinking about buffer overflow vulnerabilities, a file can sometimes
be as harmful as a packet. Even though past security issues have taught
us that it is unwise to use an unvalidated value from a file/packet as 
a text length parameter, that is what happened here.

The HtmlHelp application (hh.exe) will read a value from a .CHM file
and use this as the 'length' parameter in a REPZ MOVSD operation. 
By setting this to a large value, it is possible to overwrite sections
of the heap with attacker supplied values. 

This results in a typical win32 heap overflow landing either on the
common mov [ecx],eax / mov [eax+4],ecx pair, or on a call [eax+4]. In
either case the registers are under the control of the attacker
leading to code execution.

== Description ==

When the corrupt file is opened an exception error will first occur at

0x78010044 REPZ MOVSD

The error has occurred because the destination address has reached the end
of its allocated space. After clicking OK on the popup error box, execution
will continue until it eventually reaches.

0x77fcc663 mov [ecx],eax
0x77fcc665 mov [eax+4],ecx

At this time the EAX and ECX values have been filled with the data used to 
overwrite the heap, allowing an attacker to write an arbitrary value to 
a known place.

The corrupt file must be constructed in such a way to jump through some 
hoops first. It must pass some checks reliant on a value in the file that
sets ESI.

* This value must be valid memory
* [ESI+1c] must be non null
* [ESI+24] must be null. 

This value is simple to achieve resulting in a reliable heap exploit using
any of the multiple methods now known to exploit heap overflows.

== Exploitation ==

Remote exploitation through Internet Explorer can be obtained through the
use of the window.showhelp() function. Either using a public UNC share or
through a 'coupled' browser exploit that saves the file to a known location
before opening it. There may of course also be other ways of having a
corrupt .CHM file loaded without requiring a user to download and run it,
although a compiled help file may be easily accepted by a user anyway.

Automatic exploitation of browser based bugs, does not rely on an attacker
sending a link, requiring the target user to click on it. Links, references
and other objects can easily be opened through script code. And I am told
that this can also be achieved without script code.

== Solutions ==

- Install the vendor supplied patch.

== Credit ==

Discovered and advised to Microsoft January 12, 2004 by Brett Moore of
Security-Assessment.com

%-) Well Ruxcon rocked, so gotta say thanks to all that were there. They
%-) known who they are. Now for vegas....

== About Security-Assessment.com ==

Security-Assessment.com is a leader in intrusion testing and security
code review, and leads the world with SA-ISO, online ISO17799 compliance
management solution. Security-Assessment.com is committed to security
research and development, and its team have previously identified a
number of vulnerabilities in public and private software vendors products.


######################################################################
CONFIDENTIALITY NOTICE: 

This message and any attachment(s) are confidential and proprietary. 
They may also be privileged or otherwise protected from disclosure. If 
you are not the intended recipient, advise the sender and delete this 
message and any attachment from your system. If you are not the 
intended recipient, you are not authorised to use or copy this message 
or attachment or disclose the contents to any other person. Views 
expressed are not necessarily endorsed by Security-Assessment.com 
Limited. Please note that this communication does not designate an 
information system for the purposes of the New Zealand Electronic 
Transactions Act 2003.
######################################################################    

- 漏洞信息 (F33782)

Technical Cyber Security Alert 2004-196A (PacketStormID:F33782)
2004-07-14 00:00:00
US-CERT  us-cert.gov
advisory,remote,overflow,shell,vulnerability,code execution
windows,osx
CVE-2003-1041,CVE-2004-0201,CVE-2004-0205,CVE-2004-0210,CVE-2004-0212,CVE-2004-0213,CVE-2004-0215,CVE-2004-0420
[点击下载]

Technical Cyber Security Alert TA04-196A - Multitudes of vulnerabilities have been discovered amongst the Microsoft product line. Flaws that exist include Outlook Express failing to properly validate malformed e-mail headers, the Utility Manager allowing code execution, POSIX allowing code execution, IIS having a buffer overflow, the Task Scheduler having a buffer overflow, the HTML Help component failing to properly validate input data, and the Windows Shell allowing remote code execution.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

                        National Cyber Alert System
                   Technical Cyber Security Alert TA04-196A

Multiple Vulnerabilities in Microsoft Windows Components and Outlook Express

   Original release date: July 14, 2004
   Last revised: --
   Source: US-CERT

Systems Affected

     * Microsoft Windows Systems

Overview

   Microsoft has released a Security Bulletin Summary for July, 2004.
   This summary includes several bulletins that address vulnerabilities
   in various Windows applications and components. Exploitation of some
   vulnerabilities can result in the remote execution of arbitrary code
   by a remote attacker. Details of the vulnerabilities and their impacts
   are provided below.

I. Description

   The table below provides a reference between Microsoft's Security
   Bulletins and the related US-CERT Vulnerability Notes. More
   information related to the vulnerabilities is available in these
   documents.

   _________________________________________________________________

   Format:
 
   Microsoft Security Bulletin 

   Related US-CERT Vulnerability Note(s)
   _________________________________________________________________

   MS04-024: Vulnerability in Windows Shell Could Allow Remote Code
   Execution (839645) 

   VU#106324 Microsoft Windows contains a
   vulnerability in the way the Windows Shell launches applications
   _________________________________________________________________
   
   MS04-023: Vulnerability in HTML Help Could Allow Code Execution
   (840315) 

   VU#187196 Microsoft Windows fails to properly process
   showHelp URLs

   VU#920060 Microsoft Windows HTML Help component fails to properly
   validate input data
   _________________________________________________________________

   MS04-022: Vulnerability in Task Scheduler Could Allow Code Execution
   (841873) 

   VU#228028 Microsoft Windows Task Scheduler Buffer Overflow
   _________________________________________________________________

   MS04-021: Security Update for IIS 4.0 (841373) 

   VU#717748 Microsoft Internet Information Server (IIS) 4.0 contains a 
   buffer overflow in the redirect function
   _________________________________________________________________
    
   MS04-020: Vulnerability in POSIX Could Allow Code Execution (841872)
   
   VU#647436 Microsoft Windows contains a buffer overflow in the POSIX
   subsystem
   _________________________________________________________________
   
   MS04-019: Vulnerability in Utility Manager Could Allow Code Execution
   (842526) 

   VU#868580 Microsoft Windows Utility Manager launches applications with 
   system privileges
   _________________________________________________________________
  
   MS04-018: Cumulative Security Update for Outlook Express (823353)

   VU#869640 Microsoft Outlook Express fails to properly validate
   malformed e-mail headers
   _________________________________________________________________

II. Impact

   A remote, unauthenticated attacker may exploit VU#717748 to execute
   arbitrary code on an IIS 4.0 system.

   Exploitation of VU#106324, VU#187196, VU#920060, and VU#228028, would
   permit a remote attacker to execute arbitrary code with the privileges
   of the current user. The attacker would have to convince a victim to
   view an HTML document (web page, HTML email) or click on a crafted URI
   link.

   Vulnerabilities described in VU#647436 and VU#868580 permit a local
   user to gain elevated privileges on the local system.

   Exploitation of VU#869640 can lead to a denial-of-service condition
   against Outlook Express.

III. Solution

Apply a patch

   Microsoft has provided the patches for these vulnerabilities in the
   Security Bulletins and on Windows Update.

Do not follow unsolicited links

   It is generally a good practice not to click on unsolicited URLs
   received in email, instant messages, web forums, or Internet relay
   chat (IRC) channels. However, this practice does not always prevent
   exploitation of these types vulnerabilities. For example, a trusted
   web site could be compromised and modified to deliver exploit script
   to unsuspecting clients.

Maintain updated anti-virus software

   Anti-virus software with updated virus definitions may identify and
   prevent some exploit attempts, but variations of exploits or attack
   vectors may not be detected. Do not rely solely on anti-virus software
   to defend against these vulnerabilities. More information about
   viruses and anti-virus vendors is available on the US-CERT Computer
   Virus Resources page.

Appendix A. Vendor Information

   Specific information about these issue are available in the Security
   Bulletin Summary for July, 2004 and the US-CERT Vulnerability Notes.

Appendix B. References

     * Microsoft's Security Bulletin Summary for July, 2004 -
       <http://www.microsoft.com/technet/security/bulletin/ms04-jul.mspx>

     * US-CERT Vulnerability Note VU#106324 -
       <http://www.kb.cert.org/vuls/id/106324>

     * US-CERT Vulnerability Note VU#187196 -
       <http://www.kb.cert.org/vuls/id/187196>

     * US-CERT Vulnerability Note VU#920060 -
       <http://www.kb.cert.org/vuls/id/920060>

     * US-CERT Vulnerability Note VU#228028 -
       <http://www.kb.cert.org/vuls/id/228028>

     * US-CERT Vulnerability Note VU#717748 -
       <http://www.kb.cert.org/vuls/id/717748>

     * US-CERT Vulnerability Note VU#647436 -
       <http://www.kb.cert.org/vuls/id/647436>

     * US-CERT Vulnerability Note VU#868580 -
       <http://www.kb.cert.org/vuls/id/868580>

     * US-CERT Vulnerability Note VU#869640 -
       <http://www.kb.cert.org/vuls/id/869640>

     * Increase Your Browsing and E-Mail Safety -
       <http://www.microsoft.com/security/incident/settings.mspx>

     * Working with Internet Explorer 6 Security Settings -
       <http://www.microsoft.com/windows/ie/using/howto/security/settings
       .mspx>
   _________________________________________________________________

   This alert was created by Jason A. Rafail. Feedback can be directed to
   the Vulnerability Note authors: Jason A. Rafail, Jeff P. Lanza, Chad
   R. Dougherty, Damon G. Morda, and Art Manion.
   _________________________________________________________________

   This document is available from: 
   
      <http://www.us-cert.gov/cas/techalerts/TA04-196A.html>      
   
   _________________________________________________________________
   
   Copyright 2004 Carnegie Mellon University.
   
   Terms of use: <http://www.us-cert.gov/legal.html>
   _________________________________________________________________

   Revision History

   July 14, 2004: Initial release

                        Last updated July 14, 2004 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQFA9ZD4XlvNRxAkFWARApJoAJ9kLfHwh9rjM39LkWpRYYkPDngD+QCcDj6Q
P8VLUzmOQoMFj+903rIsKHU=
=4I7x
-----END PGP SIGNATURE-----
    

- 漏洞信息

7804
Microsoft Windows HTML Help Arbitrary Code Execution
Remote / Network Access Other
Loss of Confidentiality, Loss of Integrity, Loss of Availability
Exploit Public

- 漏洞描述

Microsoft HTML Help application (hh.exe) contains a flaw that may allow a malicious user to remotely execute code. The issue is triggered when a corrupt .chm file is opened with the Help application. It is possible that the flaw may allow arbitrary code execution resulting in a loss of confidentiality, integrity and/or availability.

- 时间线

2004-07-14 2004-01-12
2004-07-14 Unknow

- 解决方案

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released applicable patches to address this vulnerability within each respective operating system.

- 相关参考

- 漏洞作者

- 漏洞信息

Microsoft Windows HTML Help Heap Overflow Vulnerability
Boundary Condition Error 10705
Yes No
2004-07-13 12:00:00 2009-07-12 06:16:00
Discovery of this issue is credited to Brett Moore.

- 受影响的程序版本

Microsoft Windows XP Professional SP1
Microsoft Windows XP Professional
Microsoft Windows XP Home SP1
Microsoft Windows XP Home
Microsoft Windows XP 64-bit Edition Version 2003 SP1
Microsoft Windows XP 64-bit Edition Version 2003
Microsoft Windows XP 64-bit Edition SP1
Microsoft Windows XP 64-bit Edition
Microsoft Windows Server 2003 Web Edition
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows NT Workstation 4.0 SP6a
Microsoft Windows NT Workstation 4.0 SP6
Microsoft Windows NT Workstation 4.0 SP5
Microsoft Windows NT Workstation 4.0 SP4
Microsoft Windows NT Workstation 4.0 SP3
Microsoft Windows NT Workstation 4.0 SP2
Microsoft Windows NT Workstation 4.0 SP1
Microsoft Windows NT Workstation 4.0
Microsoft Windows NT Terminal Server 4.0 SP6
Microsoft Windows NT Terminal Server 4.0 SP5
Microsoft Windows NT Terminal Server 4.0 SP4
Microsoft Windows NT Terminal Server 4.0 SP3
Microsoft Windows NT Terminal Server 4.0 SP2
Microsoft Windows NT Terminal Server 4.0 SP1
Microsoft Windows NT Terminal Server 4.0
Microsoft Windows NT Server 4.0 SP6a
+ Avaya DefinityOne Media Servers
+ Avaya DefinityOne Media Servers
+ Avaya IP600 Media Servers
+ Avaya IP600 Media Servers
+ Avaya S3400 Message Application Server 0
+ Avaya S8100 Media Servers 0
+ Avaya S8100 Media Servers 0
Microsoft Windows NT Server 4.0 SP6
Microsoft Windows NT Server 4.0 SP5
Microsoft Windows NT Server 4.0 SP4
Microsoft Windows NT Server 4.0 SP3
Microsoft Windows NT Server 4.0 SP2
Microsoft Windows NT Server 4.0 SP1
Microsoft Windows NT Server 4.0
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows NT Enterprise Server 4.0 SP6
Microsoft Windows NT Enterprise Server 4.0 SP5
Microsoft Windows NT Enterprise Server 4.0 SP4
Microsoft Windows NT Enterprise Server 4.0 SP3
Microsoft Windows NT Enterprise Server 4.0 SP2
Microsoft Windows NT Enterprise Server 4.0 SP1
Microsoft Windows NT Enterprise Server 4.0
Microsoft Windows ME
Microsoft Windows 98SE
Microsoft Windows 98
Microsoft Windows 2000 Server SP4
Microsoft Windows 2000 Server SP3
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Server SP1
Microsoft Windows 2000 Server
+ Avaya DefinityOne Media Servers
+ Avaya IP600 Media Servers
+ Avaya S3400 Message Application Server 0
+ Avaya S8100 Media Servers 0
Microsoft Windows 2000 Professional SP4
Microsoft Windows 2000 Professional SP3
Microsoft Windows 2000 Professional SP2
Microsoft Windows 2000 Professional SP1
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows 2000 Datacenter Server SP3
Microsoft Windows 2000 Datacenter Server SP2
Microsoft Windows 2000 Datacenter Server SP1
Microsoft Windows 2000 Datacenter Server
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows 2000 Advanced Server SP1
Microsoft Windows 2000 Advanced Server
Avaya S8100 Media Servers 0
+ Microsoft Windows 2000 Server
+ Microsoft Windows NT Server 4.0 SP6a
Avaya S3400 Message Application Server 0
+ Microsoft Windows 2000 Server
Avaya IP600 Media Servers
Avaya DefinityOne Media Servers

- 漏洞讨论

The Microsoft Windows HTML Help facility is prone to a remotely exploitable heap overflow vulnerability. This vulnerability could be exploited from a malicious Web page or through HTML email to execute arbitrary code with the privileges of the currently logged in user.

- 漏洞利用

The researcher who discovered this vulnerability has developed working exploit code that is not publicly available or known to be circulating in the wild.

- 解决方案

Microsoft has released patches to address this issue for all supported platforms.

Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Avaya advise that customers follow the Microsoft recommendations to address this issue. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=197331&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()


Microsoft Windows 2000 Server SP2

Microsoft Windows 2000 Advanced Server SP2

Microsoft Windows Server 2003 Enterprise Edition Itanium 0

Microsoft Windows Server 2003 Standard Edition

Microsoft Windows XP Professional

Microsoft Windows Server 2003 Datacenter Edition Itanium 0

Microsoft Windows XP 64-bit Edition SP1

Microsoft Windows Server 2003 Datacenter Edition

Microsoft Windows 2000 Advanced Server SP4

Microsoft Windows 2000 Professional SP3

Microsoft Windows Server 2003 Enterprise Edition

Microsoft Windows 2000 Professional SP2

Microsoft Windows 2000 Datacenter Server SP4

Microsoft Windows Server 2003 Web Edition

Microsoft Windows 2000 Advanced Server SP3

Microsoft Windows XP Home

Microsoft Windows XP Home SP1

Microsoft Windows XP 64-bit Edition Version 2003 SP1

Microsoft Windows 2000 Datacenter Server SP3

Microsoft Windows 2000 Server SP3

Microsoft Windows XP 64-bit Edition Version 2003

Microsoft Windows XP 64-bit Edition

Microsoft Windows 2000 Datacenter Server SP2

Microsoft Windows 2000 Server SP4

Microsoft Windows 2000 Professional SP4

Microsoft Windows XP Professional SP1

- 相关参考

 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站