Buffer Overrun in Winhlp32.exe

A buffer overrun vulnerability exists in winhlp32.exe that can result in the execution of arbitrary code on the vulnerable system.

Ken Pfeil

August 13, 2002

2 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported August 1, 2002, by MarkLitchfield.

VERSION AFFECTED

· Windows 2000 Service Pack 2 (SP2) winhlp32.exe

DESCRIPTION

A buffer overrun vulnerability exists in winhlp32.exe that can result in the execution of arbitrary code on the vulnerable system. This vulnerability stems from a flaw in the WinHlp command's Item parameter. This exploit would execute in the security context of the currently logged-on user. A detailed advisory is available on the discoverer’s Web site.

 

DEMONSTRATION

Thediscoverer posted the following demonstration, which will display Calculatorunder Win2K SP2 as proof-of-concept:

VENDOR RESPONSE

Thevendor, Microsoft, has released Win2KSP3, which includes a fix for this vulnerability.

CREDIT
Discoveredby Mark Litchfield of NGSSoftware.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like