HTTP: Malformed Microsoft HLP/CHM File
This signature detects attempts to exploit a known vulnerability in the Microsoft Help file format. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the user.
Extended Description
The Microsoft Windows Help File viewer (winhlp32.exe) is reported prone to a heap-overflow vulnerability. This vulnerability presents itself when the application handles a specially crafted Windows Help (.hlp) file. A successful attack may facilitate arbitrary code execution in the context of a vulnerable user who opens a malicious file.
Affected Products
Microsoft windows_xp_media_center_edition
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Microsoft
4.0
5.1