Vulnerabilities > CVE-2007-0352 - Buffer Overflow vulnerability in Microsoft Html Help Workshop 4.02.0002
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt file composed of lines that begin with an integer followed by a space and a long string.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Microsoft Help Workshop 4.03.0002 (.CNT) Buffer Overflow Exploit. CVE-2007-0352,CVE-2007-0427. Local exploit for windows platform |
file | exploits/windows/local/3149.cpp |
id | EDB-ID:3149 |
last seen | 2016-01-31 |
modified | 2007-01-17 |
platform | windows |
port | |
published | 2007-01-17 |
reporter | porkythepig |
source | https://www.exploit-db.com/download/3149/ |
title | Microsoft Help Workshop 4.03.0002 - .CNT Buffer Overflow Exploit |
type | local |
Saint
bid | 22100 |
description | Microsoft Help Workshop .CNT file buffer overflow |
id | misc_mshelpworkshop |
osvdb | 31898 |
title | microsoft_help_workshop_cnt |
type | client |
References
- http://osvdb.org/31898
- http://secunia.com/advisories/23862
- http://securityreason.com/securityalert/2156
- http://securitytracker.com/id?1017530
- http://www.anspi.pl/~porkythepig/visualization/cnt-expl1.cpp
- http://www.securityfocus.com/archive/1/457210/100/0/threaded
- http://www.securityfocus.com/bid/22100
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31555
- https://www.exploit-db.com/exploits/3149