The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Unchecked Buffer in Windows Help Facility Could Enable Code Execution (Q323255)
Time: 02:00 EST/07:00 GMT | News Source: Microsoft | Posted By: Byron Hinson

The HTML Help facility in Windows includes an ActiveX control that provides much of its functionality. One of the functions exposed via the control contains an unchecked buffer, which could be exploited by a web page hosted on an attacker’s site or sent to a user as an HTML mail. An attacker who successfully exploited the vulnerability would be able to run code in the security context of the user, thereby gaining the same privileges as the user on the system.

A second vulnerability exists because of flaws associated with the handling of compiled HTML Help (.chm) files that contain shortcuts. Because shortcuts allow HTML Help files to take any desired action on the system, only trusted HTML Help files should be allowed to use them. Two flaws allow this restriction to be bypassed. First, the HTML Help facility incorrectly determines the Security Zone in the case where a web page or HTML mail delivers a .chm file to the Temporary Internet Files folder and subsequently opens it. Instead of handling the .chm file in the correct zone – the one associated with the web page or HTML mail that delivered it – the HTML Help facility incorrectly handles it in the Local Computer Zone, thereby considering it trusted and allowing it to use shortcuts. This error is compounded by the fact that the HTML Help facility doesn’t consider what folder the content resides in. Were it to do so, it could recover from the first flaw, as content within the Temporary Internet Folder is clearly not trusted, regardless of the Security Zone it renders in.

The attack scenario for this vulnerability would be complex, and involves using an HTML mail to deliver a .chm file that contains a shortcut, then making use of the flaws to open it and allow the shortcut to execute. The shortcut would be able to perform any action the user had privileges to perform on the system.

Patch availability

Download locations for this patch
The patches for all Windows systems are available via Windows Update or can be manually applied via the following patches:

Write Comment
Return to News

  Displaying 576 through 600 of 627
Prev | First | Last | Next
  The time now is 8:20:22 PM ET.
Any comment problems? E-mail us
#576 By 4240821 (82.115.4.230) at 7/29/2025 11:33:43 PM
https://justpaste.me/bzIV2
https://justpaste.me/cP5i2
https://justpaste.me/bHMM5
https://justpaste.me/cMMu1
https://justpaste.me/fAem1
https://justpaste.me/a1bw
https://justpaste.me/a3Io
https://justpaste.me/bmdv
https://justpaste.me/Zmlq1
https://justpaste.me/dUfX2

#577 By 4240821 (82.115.4.230) at 7/31/2025 5:06:11 PM
https://justpaste.me/dnm32
https://justpaste.me/fA00
https://justpaste.me/beF31
https://justpaste.me/dgaD2
https://justpaste.me/cEwR3
https://justpaste.me/eZno
https://justpaste.me/aypj3
https://justpaste.me/fpjP2
https://justpaste.me/ePdv4
https://justpaste.me/ftKe7

#578 By 4240821 (82.115.4.230) at 8/1/2025 9:53:42 AM
https://justpaste.me/fkab2
https://justpaste.me/fO59
https://justpaste.me/fC55
https://justpaste.me/dIX84
https://justpaste.me/d0zh3
https://justpaste.me/Zwa01
https://justpaste.me/f7XG3
https://justpaste.me/ZWDu4
https://justpaste.me/Zphy
https://justpaste.me/dF0C4

#579 By 4240821 (82.115.4.230) at 8/2/2025 8:26:24 AM
https://justpaste.me/ejfS
https://justpaste.me/doAN4
https://justpaste.me/auSp
https://justpaste.me/dE9y
https://justpaste.me/g30N
https://justpaste.me/ae0M2
https://justpaste.me/aqJd5
https://justpaste.me/cQ8n1
https://justpaste.me/cI9C1
https://justpaste.me/dJuL

#580 By 4240821 (82.115.4.230) at 8/2/2025 6:51:38 PM
https://justpaste.me/dCD2
https://justpaste.me/adrD3
https://justpaste.me/eGjM
https://justpaste.me/bM8K
https://justpaste.me/aG19
https://justpaste.me/ft7z3
https://justpaste.me/eCyK
https://justpaste.me/cDl1
https://justpaste.me/aeJm1
https://justpaste.me/dQEl5

#581 By 4240821 (82.115.4.230) at 8/3/2025 11:21:58 AM
https://justpaste.me/c94J
https://justpaste.me/ejrG1
https://justpaste.me/ap374
https://justpaste.me/ZtWr2
https://justpaste.me/fZeF5
https://justpaste.me/fdHk2
https://justpaste.me/d6R4
https://justpaste.me/bRRr2
https://justpaste.me/fvuW2
https://justpaste.me/dht3

#582 By 4240821 (82.115.4.230) at 8/3/2025 9:33:57 PM
https://justpaste.me/bEBd3
https://justpaste.me/bcZh5
https://justpaste.me/Z9xq
https://justpaste.me/ZIDA1
https://justpaste.me/ZmYu4
https://justpaste.me/Zs0k2
https://justpaste.me/eoCd6
https://justpaste.me/fv4k1
https://justpaste.me/ebtD3
https://justpaste.me/fuOZ3

#583 By 4240821 (82.115.4.230) at 8/4/2025 5:28:34 PM
https://moanio.com/video.php?id=377
https://moanio.com/video.php?id=153
https://moanio.com/video.php?id=807
https://moanio.com/video.php?id=4747
https://moanio.com/video.php?id=1420
https://moanio.com/video.php?id=3404
https://moanio.com/video.php?id=2741
https://moanio.com/video.php?id=6093
https://moanio.com/video.php?id=1386
https://moanio.com/video.php?id=149

#584 By 4240821 (82.115.4.230) at 8/5/2025 12:49:26 AM
https://moanio.com/video.php?id=3854
https://moanio.com/video.php?id=4136
https://moanio.com/video.php?id=720
https://moanio.com/video.php?id=3779
https://moanio.com/video.php?id=4137
https://moanio.com/video.php?id=5851
https://moanio.com/video.php?id=848
https://moanio.com/video.php?id=4827
https://moanio.com/video.php?id=6620
https://moanio.com/video.php?id=1229

#585 By 4240821 (82.115.4.230) at 8/5/2025 2:44:24 PM
https://moanio.com/video.php?id=807
https://moanio.com/video.php?id=2698
https://moanio.com/video.php?id=315
https://moanio.com/video.php?id=1953
https://moanio.com/video.php?id=532
https://moanio.com/video.php?id=5964
https://moanio.com/video.php?id=5000
https://moanio.com/video.php?id=2100
https://moanio.com/video.php?id=4339
https://moanio.com/video.php?id=2212

#586 By 4240821 (82.115.4.230) at 8/6/2025 1:47:50 AM
https://moanio.com/video.php?id=2306
https://moanio.com/video.php?id=3336
https://moanio.com/video.php?id=6786
https://moanio.com/video.php?id=1375
https://moanio.com/video.php?id=5835
https://moanio.com/video.php?id=7061
https://moanio.com/video.php?id=7235
https://moanio.com/video.php?id=4423
https://moanio.com/video.php?id=4873
https://moanio.com/video.php?id=7135

#587 By 4240821 (82.115.4.230) at 8/7/2025 10:43:45 AM
https://moanio.com/video.php?id=6614
https://moanio.com/video.php?id=2012
https://moanio.com/video.php?id=3643
https://moanio.com/video.php?id=1661
https://moanio.com/video.php?id=197
https://moanio.com/video.php?id=2122
https://moanio.com/video.php?id=3434
https://moanio.com/video.php?id=2136
https://moanio.com/video.php?id=5038
https://moanio.com/video.php?id=4470

#588 By 4240821 (82.115.4.230) at 8/7/2025 11:03:57 PM
https://moanio.com/video.php?id=1405
https://moanio.com/video.php?id=622
https://moanio.com/video.php?id=2102
https://moanio.com/video.php?id=6562
https://moanio.com/video.php?id=4630
https://moanio.com/video.php?id=6880
https://moanio.com/video.php?id=3433
https://moanio.com/video.php?id=945
https://moanio.com/video.php?id=7160
https://moanio.com/video.php?id=5424

#589 By 4240821 (82.115.4.230) at 8/8/2025 2:09:44 AM
https://moanio.com/video.php?id=2039
https://moanio.com/video.php?id=3307
https://moanio.com/video.php?id=548
https://moanio.com/video.php?id=5533
https://moanio.com/video.php?id=3749
https://moanio.com/video.php?id=2242
https://moanio.com/video.php?id=1001
https://moanio.com/video.php?id=1355
https://moanio.com/video.php?id=4831
https://moanio.com/video.php?id=6572

#590 By 4240821 (82.115.4.230) at 8/8/2025 11:53:09 PM
https://moanio.com/video.php?id=1828
https://moanio.com/video.php?id=1432
https://moanio.com/video.php?id=5887
https://moanio.com/video.php?id=4090
https://moanio.com/video.php?id=5356
https://moanio.com/video.php?id=2752
https://moanio.com/video.php?id=3651
https://moanio.com/video.php?id=5728
https://moanio.com/video.php?id=7015
https://moanio.com/video.php?id=255

#591 By 4240821 (82.115.4.230) at 8/10/2025 2:08:32 AM
https://moanio.com/video.php?id=5467
https://moanio.com/video.php?id=2625
https://moanio.com/video.php?id=5653
https://moanio.com/video.php?id=509
https://moanio.com/video.php?id=3288
https://moanio.com/video.php?id=5899
https://moanio.com/video.php?id=6244
https://moanio.com/video.php?id=6754
https://moanio.com/video.php?id=1401
https://moanio.com/video.php?id=910

#592 By 4240821 (82.115.4.230) at 8/10/2025 4:56:14 PM
https://moanio.com/video.php?id=197
https://moanio.com/video.php?id=254
https://moanio.com/video.php?id=1613
https://moanio.com/video.php?id=6786
https://moanio.com/video.php?id=4634
https://moanio.com/video.php?id=2877
https://moanio.com/video.php?id=6266
https://moanio.com/video.php?id=4562
https://moanio.com/video.php?id=7068
https://moanio.com/video.php?id=3686

#593 By 4240821 (82.115.4.230) at 8/11/2025 2:42:56 AM
https://www.xfree.com/focadisti186
https://www.xfree.com/luomivilcough38
https://www.xfree.com/terabkexa6
https://www.xfree.com/quomastcessper454
https://www.xfree.com/fifadeca447
https://www.xfree.com/cudesctertwin246
https://www.xfree.com/butimonte349
https://www.xfree.com/profarhyci993
https://www.xfree.com/siobotasa596
https://www.xfree.com/tiovecubsi56

#594 By 4240821 (82.115.4.230) at 8/11/2025 8:59:11 PM
https://www.xfree.com/etrutaty61
https://www.xfree.com/lotaldayfor391
https://www.xfree.com/marciromwo562
https://www.xfree.com/afinsenzie318
https://www.xfree.com/propramuma800
https://www.xfree.com/crobomloncomp620
https://www.xfree.com/busnidoter782
https://www.xfree.com/excibardio144
https://www.xfree.com/propramuma800
https://www.xfree.com/trancarsimpfab810

#595 By 4240821 (82.115.4.230) at 8/12/2025 2:48:27 PM
https://www.xfree.com/tezgogepost421
https://www.xfree.com/ghagoregaw378
https://www.xfree.com/restpartato284
https://www.xfree.com/liatrophibpe107
https://www.xfree.com/brasacsearchi975
https://www.xfree.com/neiglobicboc971
https://www.xfree.com/gaychronesin288
https://www.xfree.com/topsygibrei824
https://www.xfree.com/liavidanoc259
https://www.xfree.com/neyskathaga844

#596 By 4240821 (82.115.4.230) at 8/13/2025 10:02:56 AM
https://www.xfree.com/beltcountpere790
https://www.xfree.com/dertucoli771
https://www.xfree.com/joesauprosal10
https://www.xfree.com/hostrocsynchlong672
https://www.xfree.com/venfolkwoodbsen462
https://www.xfree.com/restpartato284
https://www.xfree.com/onefunnur814
https://www.xfree.com/biosvagelot260
https://www.xfree.com/taistomfoxggard483
https://www.xfree.com/ghagoregaw378

#597 By 4240821 (82.115.4.230) at 8/14/2025 6:55:05 AM
https://www.xfree.com/mounbotifi734
https://www.xfree.com/spynrazopo262
https://www.xfree.com/tramovwoma576
https://www.xfree.com/roundperlega498
https://www.xfree.com/twigupouttrag595
https://www.xfree.com/windcontailo920
https://www.xfree.com/breakeminrie951
https://www.xfree.com/sihalftesi135
https://www.xfree.com/granenkonwhoe63
https://www.xfree.com/liojeancuybreak583

#598 By 4240821 (82.115.4.230) at 8/14/2025 8:35:59 AM
https://www.xfree.com/fisuhampchefs182
https://www.xfree.com/ferpadumpvirb287
https://www.xfree.com/gurgverwordlo315
https://www.xfree.com/exfivithy655
https://www.xfree.com/rutoothflabna890
https://www.xfree.com/flowesetlan377
https://www.xfree.com/faumaworkcan309
https://www.xfree.com/enkitvaca975
https://www.xfree.com/ramsjusttene30
https://www.xfree.com/scambolguege823

#599 By 4240821 (82.115.4.230) at 8/15/2025 8:19:34 PM
https://www.xfree.com/instaginin745
https://www.xfree.com/vlogorphering852
https://www.xfree.com/geschvinrguagi549
https://www.xfree.com/lengcagepa80
https://www.xfree.com/unrompoonsmi819
https://www.xfree.com/ickaposimp624
https://www.xfree.com/reobubele792
https://www.xfree.com/tairosice593
https://www.xfree.com/wiburlicomp172
https://www.xfree.com/liicrotelin658

#600 By 4240821 (82.115.4.230) at 8/15/2025 9:25:42 PM
https://www.xfree.com/depopgolfpen1
https://www.xfree.com/tumbtentbangcom496
https://www.xfree.com/bracungarva201
https://www.xfree.com/antrifhuangre375
https://www.xfree.com/timoroho802
https://www.xfree.com/erdeletzbo904
https://www.xfree.com/mibadible610
https://www.xfree.com/sicolmowor20
https://www.xfree.com/intinedu387
https://www.xfree.com/halrecamarb157

Write Comment
Return to News
  Displaying 576 through 600 of 627
Prev | First | Last | Next
  The time now is 8:20:22 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *