Overview
Microsoft HTML Help contains an integer overflow vulnerability, allowing a remote attacker to execute arbitrary code.
Description
HTML Help The Microsoft HTML Help system ". . . is the standard help system for the Windows platform." HTML Help components can be compiled to ". . . compress HTML, graphic, and other files into a relatively small compiled help (.chm) file. . ." The resulting compiled Help (CHM) file can then ". . . be distributed with a software application, or downloaded from the Web." The Help Viewer application ". . . uses the underlying components of Microsoft Internet Explorer to display help content. It supports HTML, ActiveX, Java, scripting languages (JScript, and Microsoft Visual Basic Scripting Edition). . ." ms-its:http://www.example.com/directory/path/compiledhelpfile.chm:/htmlfile.html This URL references a local CHM file: its:file://c:\directory\path\compiledhelpfile.chm:/htmlfile.html The Problem |
Impact
By convincing a victim to view a specially crafted CHM file, an attacker could execute arbitrary code with the privileges of the user. By using one of the InfoTech Storage Format protocols, such as ms-its, an attacker can cause open an arbitrary CHM file as the result of viewing an HTML document (web page, HTML email). |
Solution
Upgrade or patch |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.microsoft.com/technet/security/bulletin/MS05-026.mspx
- http://www.ngssoftware.com/advisories/msitss.txt
- http://www.eeye.com/html/research/advisories/AD20050614.html
- http://secunia.com/advisories/15683/
- http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33045
- http://www.osvdb.org/displayvuln.php?osvdb_id=17305
Acknowledgements
Thanks to Microsoft for reporting this vulnerability. Microsoft, in turn, credits eEye Digital Security and Peter Winter-Smith of Next Generation Security Software Ltd
This document was written by Will Dormann and is based on information provided by eEye Digital Security.
Other Information
CVE IDs: | CVE-2005-1208 |
Severity Metric: | 36.35 |
Date Public: | 2005-06-14 |
Date First Published: | 2005-06-14 |
Date Last Updated: | 2005-06-27 16:53 UTC |
Document Revision: | 15 |