Skip to main content

New Bug Reported In Windows Help Files

posted onApril 13, 2007
by hitbsecnews

Another Microsoft vulnerability has been disclosed, along with proof-of-concept code.

The so-called heap-overflow vulnerability affects Windows help files in multiple versions of Windows XP, Windows Server 2003, Windows NT, and Windows 2000. Researchers at Security Focus reported that the Help File viewer is prone to a heap-overflow vulnerability because it fails to perform boundary checks before copying user-supplied data into insufficiently sized memory buffers.

The problem arises when the application handles a malformed or malicious Windows Help File.

"A successful attack may facilitate arbitrary code execution in the context of a vulnerable user who opens a malicious file," wrote a Security Focus researcher in an advisory. "Failed exploit attempts will likely result in denial-of-service conditions."

Source

Tags

Microsoft

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th