Windows HTML Help Could Allow Remote Code Execution

A vulnerability in the HTML ActiveX Control component could allow an intruder to gain control over a remote machine if a user visits a Web site designed to exploit the vulnerability.

ITPro Today

January 10, 2005

1 Min Read
ITPro Today logo in a gray background | ITPro Today

ReportedDecember 23, 2004, by flashsky fangxing

VERSIONS AFFECTED

  • Windows Server 2003

  • Windows XP

  • Windows 2000

  • Windows Me

  • Windows 9x

DESCRIPTION

A vulnerability in theHTML ActiveX Control component could allow an intruder to gaincontrol over a remote machine if a user visits a Web site designed toexploit the vulnerability.

VENDOR RESPONSE

Microsoft has issuedSecurity Bulletin MS05-001, “Vulnerabilityin HTML Help Could Allow Code Execution (890175),”to address this critical issue.

CREDIT

Discovered by flashskyfangxing

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like