The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Unchecked Buffer in Windows Help Facility Could Enable Code Execution (Q323255)
Time: 02:00 EST/07:00 GMT | News Source: Microsoft | Posted By: Byron Hinson

The HTML Help facility in Windows includes an ActiveX control that provides much of its functionality. One of the functions exposed via the control contains an unchecked buffer, which could be exploited by a web page hosted on an attacker’s site or sent to a user as an HTML mail. An attacker who successfully exploited the vulnerability would be able to run code in the security context of the user, thereby gaining the same privileges as the user on the system.

A second vulnerability exists because of flaws associated with the handling of compiled HTML Help (.chm) files that contain shortcuts. Because shortcuts allow HTML Help files to take any desired action on the system, only trusted HTML Help files should be allowed to use them. Two flaws allow this restriction to be bypassed. First, the HTML Help facility incorrectly determines the Security Zone in the case where a web page or HTML mail delivers a .chm file to the Temporary Internet Files folder and subsequently opens it. Instead of handling the .chm file in the correct zone – the one associated with the web page or HTML mail that delivered it – the HTML Help facility incorrectly handles it in the Local Computer Zone, thereby considering it trusted and allowing it to use shortcuts. This error is compounded by the fact that the HTML Help facility doesn’t consider what folder the content resides in. Were it to do so, it could recover from the first flaw, as content within the Temporary Internet Folder is clearly not trusted, regardless of the Security Zone it renders in.

The attack scenario for this vulnerability would be complex, and involves using an HTML mail to deliver a .chm file that contains a shortcut, then making use of the flaws to open it and allow the shortcut to execute. The shortcut would be able to perform any action the user had privileges to perform on the system.

Patch availability

Download locations for this patch
The patches for all Windows systems are available via Windows Update or can be manually applied via the following patches:

Write Comment
Return to News

  Displaying 701 through 706 of 706
Prev | First
  The time now is 12:20:02 AM ET.
Any comment problems? E-mail us
#701 By 4240821 (208.123.185.42) at 11/26/2025 11:55:26 PM
https://lustful.su/activ5cbg412h12
https://sexonly.su/activ13df3g455e
https://sluts.su/activ2gaa5d4d1c
https://smutty.su/activ3c11adhd1f
https://nsfw.su/activ2bd3ac2cbc
https://lustful.su/active5b32fbahh
https://sluts.su/activ2g4g4gc1eh
https://sexonly.su/activ4hdh1hdd53
https://sluts.su/activh1cf43a441
https://smutty.su/activbg2b1dd24g

#702 By 4240821 (208.123.185.42) at 11/27/2025 6:45:31 AM
https://sexonly.su/activf3g33g5ega
https://lustful.su/activaeafhhga45
https://sluts.su/activ4dffde2d1a
https://nsfw.su/activ1fcf1eg2h4
https://smutty.su/activ4dh1debhfd
https://lustful.su/activd351ccebgg
https://smutty.su/activ311ge1b13d
https://nsfw.su/activa2f5bh12b5
https://sluts.su/activcb4f34fgdf
https://sexonly.su/activ5fdbac1beh

#703 By 4240821 (208.123.185.42) at 11/27/2025 4:10:22 PM
https://telegra.ph/Prague-Playoffs-Ignite-Citys-Passion-Unforgettable-Showdown-Sets-Record-Crowd-Ablaze-11-21
https://telegra.ph/alex-carey-unleashes-a-record-breaking-performance-sending-fans-into-a-frenzy-11-21
https://telegra.ph/Bucky-Irving-Sparks-Internet-Frenzy-with-Jaw-Dropping-Night-11-21
https://telegra.ph/Magis-TV-Revolutionizes-Streaming-with-Unmatched-Content-and-Cutting-Edge-Technology-11-21
https://telegra.ph/Gambias-Surprising-Economic-Boom-How-a-Small-Nation-is-Outpacing-Larger-Neighbors-11-21
https://telegra.ph/posten-cup-Sparks-Electric-Upset-as-Underdogs-Stun-Top-Seeds-11-21-3
https://telegra.ph/Kevin-Kilbane-Unleashes-Fiery-Comeback-That-Has-Fans-Roaring-11-21-3
https://telegra.ph/Sunrise-on-the-Reaping-Harvest-of-Hope-Begins-11-21-2
https://telegra.ph/danmark-sverige-håndbold-Explosive-Showdown-Sparks-Global-Hype-as-Rivalry-Captivates-Fans-11-21-2
https://telegra.ph/Massive-Thanksgiving-Celebration-Sets-New-Record-for-Food-and-Gratitude-11-21

#704 By 4240821 (208.123.185.42) at 11/27/2025 7:33:29 PM
https://nsfw.su/activb15f5c4b5c
https://sluts.su/activ2fe3bg53ec
https://sluts.su/activ2eda5fee2g
https://nsfw.su/activ3dh555hb2f
https://sexonly.su/activg4e455d5fb
https://sexonly.top/active23ad2f5gg
https://sexonly.top/activ4gefef4f3c
https://nsfw.su/activ54b514afa5
https://sexonly.top/activce51cbfh1d
https://sexonly.su/activhhhchag4gh

#705 By 4240821 (208.123.185.42) at 11/28/2025 11:24:23 AM
https://sexonly.su/activ443eh4c54h
https://lustful.su/activc2344gc2h3
https://sexonly.top/activc24fhc4a1c
https://sluts.su/activ3hb2bhae4g
https://sexonly.top/activ22caegf4e4
https://sexonly.top/activ1b4ecc5f3f
https://smutty.su/activ5be23h1b2d
https://sexonly.su/activf34bagg4aa
https://sluts.su/activ2a13g212g5
https://sexonly.su/activ11hfghfgd2

#706 By 4240821 (208.123.185.42) at 11/29/2025 12:15:27 AM
https://sexonly.su/activgg233252a5
https://sexonly.su/activchc1ca21f5
https://sexonly.su/activfgb2f3g3f1
https://nsfw.su/activ21bhdcf11c
https://sluts.su/activfb12d5cb3f
https://smutty.su/activ1d5bdae5e5
https://smutty.su/activdbdfchf1f5
https://sexonly.su/activ1badhe3fff
https://nsfw.su/activ1ea5af15dc
https://nsfw.su/activ3fd14d3dg1

Write Comment
Return to News
  Displaying 701 through 706 of 706
Prev | First
  The time now is 12:20:02 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *