Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Help Workshop .HPJ File Buffer Overflow Vulnerability

Microsoft Help Workshop fails to properly bounds-check user-supplied input in '.hpj' help project files.

An attacker may use a malformed '.hpj' file containing an unusually long string to cause a stack-based buffer overflow, allowing the execution of arbitrary code.

A successful exploit would result in the execution of arbitrary code within the security context of the user running the affected application.







 

Privacy Statement
Copyright 2009, SecurityFocus