← Back

CVE-2004-1361

nvd nist
Published: Dec 23, 2004Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a malformed .hlp file, which leads to a heap-based buffer overflow.

Affected (56)

4 products
Windows 2000
Windows 2003 Server
Windows Nt
Windows Xp
Configuration A
56 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
All versions
All versions
All versions
All versions
All versions
Microsoft
Version enterprise
Version enterprise sp1_beta_1
Version enterprise_64-bit
Version r2
Version r2
Version r2 sp1_beta_1
Version standard
Version standard sp1_beta_1
Version web
Version web sp1_beta_1
Microsoft
Version 4.0
Version 4.0
Version 4.0
Version 4.0
Version 4.0 sp1
Version 4.0 sp1
Version 4.0 sp1
Version 4.0 sp1
Version 4.0 sp2
Version 4.0 sp2
Version 4.0 sp2
Version 4.0 sp2
Version 4.0 sp3
Version 4.0 sp3
Version 4.0 sp3
Version 4.0 sp3
Version 4.0 sp4
Version 4.0 sp4
Version 4.0 sp4
Version 4.0 sp4
Version 4.0 sp5
Version 4.0 sp5
Version 4.0 sp5
Version 4.0 sp5
Version 4.0 sp6
Version 4.0 sp6
Version 4.0 sp6
Version 4.0 sp6
Version 4.0 sp6a
Version 4.0 sp6a
Version 4.0 sp6a
Version 4.0 sp6a
Microsoft
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions

References (8)

Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.