Vulnerability Description
Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.
Affected Platforms (CPE)
💻
Windows 2000
All versions💻
Windows 2003 Server
= 64-bit💻
Windows 2003 Server
= datacenter_64-bit💻
Windows 2003 Server
= datacenter_64-bit💻
Windows 2003 Server
= enterprise💻
Windows 2003 Server
= enterprise💻
Windows 2003 Server
= enterprise💻
Windows 2003 Server
= enterprise_64-bit💻
Windows 2003 Server
= enterprise_64-bit💻
Windows 2003 Server
= enterprise_64-bit💻
Windows 2003 Server
= standard💻
Windows 2003 Server
= standard💻
Windows 2003 Server
= standard💻
Windows 2003 Server
= standard_64-bit💻
Windows 2003 Server
= web💻
Windows 2003 Server
= web💻
Windows 2003 Server
= web