CERT-In Vulnerability Note
CIVN-2005-0049
Microsoft Windows HTML Help Remote Code Execution
Original Issue Date:June 15, 2005
Severity Rating: HIGH
Systems Affected
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server
- Microsoft Windows Server 2003 Datacenter Edition
- Microsoft Windows Server 2003 Enterprise Edition
- Microsoft Windows Server 2003 Standard Edition
- Microsoft Windows Server 2003 Web Edition
- Microsoft Windows XP Home Edition
- Microsoft Windows XP Professional
Overview
A remote code execution vulnerability exists in Windows HTML Help which could allow an attacker to execute arbitrary commands on the affected system.
Description
Microsoft HTML Help is the standard help system for the Windows platform which is used to create online Help files for a software application or Website.
This vulnerability is caused due to an input validation error within HTML Help. To exploit this vulnerability an attacker could host a malicious webpage and convince the target user to click the malicious link, which allows an attacker to gain complete control of an affected system.
Workaround
Unregister HTML Help InfoTech Protocol Click Start, click Run, type regsvr32 /u windir \system32\itss.dll, and then click OK.
Solution
Apply the appropriate patches as mentioned in Microsoft Security Bulletin
MS05-026
Vendor Information
Microsoft Corporation
http://www.microsoft.com/technet/security/Bulletin/MS05-026.mspx
References
Vulnerability Note VU#851869
http://www.kb.cert.org/vuls/id/851869
Secunia Advisory SA15694
http://secunia.com/advisories/15683/
CVE Name
CAN-2005-1208
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|