Vulnerabilities > CVE-2007-0427 - Buffer Overflow vulnerability in Microsoft Html Help Workshop 4.03.0002

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
microsoft
critical
exploit available

Summary

Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section.

Vulnerable Configurations

Part Description Count
Application
Microsoft
1

Exploit-Db

descriptionMicrosoft Help Workshop 4.03.0002 (.CNT) Buffer Overflow Exploit. CVE-2007-0352,CVE-2007-0427. Local exploit for windows platform
fileexploits/windows/local/3149.cpp
idEDB-ID:3149
last seen2016-01-31
modified2007-01-17
platformwindows
port
published2007-01-17
reporterporkythepig
sourcehttps://www.exploit-db.com/download/3149/
titleMicrosoft Help Workshop 4.03.0002 - .CNT Buffer Overflow Exploit
typelocal

Saint

bid22135
descriptionMicrosoft Help Workshop .HPJ file HLP field buffer overflow
idmisc_mshelpworkshop
osvdb31899
titlemicrosoft_help_workshop_hlp
typeclient