Buffer Overrun in Winhlp32.exe
A buffer overrun vulnerability exists in winhlp32.exe that can result in the execution of arbitrary code on the vulnerable system.
August 13, 2002
Reported August 1, 2002, by MarkLitchfield.
VERSION AFFECTED
· Windows 2000 Service Pack 2 (SP2) winhlp32.exe
DESCRIPTION
A buffer overrun vulnerability exists in winhlp32.exe that can result in the execution of arbitrary code on the vulnerable system. This vulnerability stems from a flaw in the WinHlp command's Item parameter. This exploit would execute in the security context of the currently logged-on user. A detailed advisory is available on the discoverer’s Web site.
DEMONSTRATION
Thediscoverer posted the following demonstration, which will display Calculatorunder Win2K SP2 as proof-of-concept:
VENDOR RESPONSE
Thevendor, Microsoft, has released Win2KSP3, which includes a fix for this vulnerability.
CREDIT
Discoveredby Mark Litchfield of NGSSoftware.
About the Author
You May Also Like