Vulnerabilities > CVE-2004-1306 - Heap Overflow vulnerability in Microsoft Windows winhlp32 Phrase

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
microsoft
exploit available

Summary

Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a crafted .hlp file.

Exploit-Db

descriptionMicrosoft Windows 2000/2003/XP winhlp32 Phrase Integer Overflow Vulnerability. CVE-2004-1306 . Remote exploit for windows platform
idEDB-ID:25049
last seen2016-02-03
modified2004-12-23
published2004-12-23
reporterflashsky fangxing
sourcehttps://www.exploit-db.com/download/25049/
titleMicrosoft Windows 2000/2003/XP winhlp32 Phrase Integer Overflow Vulnerability