CVE-2004-1306
Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a crafted .hlp file.
- Affected products
- Windows 2000, Windows 2003, Windows Nt, Windows Xp, Winhlp32.Exe
- Microsoft Windows 2000
- All versions
- Microsoft Windows 2003 Server
- = datacenter_64-bit, enterprise, enterprise_64-bit, R2, standard, web
- Microsoft Windows Nt
- = 4.0
- Microsoft Windows Xp
- All versions
- Fix
- Available
- CVSS 2.0
- 5.1 MEDIUM
- EPSS
- 19.6% (97th percentile)
- NVD status
- Modified
- Published
- 2005-01-19
CVE-2004-1306 at NVD
1 known exploit for CVE-2004-1306
Proof-of-concept code and exploit modules indexed by Sploitus