CVE Vulnerabilities

CVE-2004-1361

Published: Dec 23, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a malformed .hlp file, which leads to a heap-based buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
Windows_2000Microsoft**
Windows_2003_serverMicrosoftenterprise (including)enterprise (including)
Windows_2003_serverMicrosoftenterprise-sp1_beta_1 (including)enterprise-sp1_beta_1 (including)
Windows_2003_serverMicrosoftenterprise_64-bit (including)enterprise_64-bit (including)
Windows_2003_serverMicrosoftr2 (including)r2 (including)
Windows_2003_serverMicrosoftr2-sp1_beta_1 (including)r2-sp1_beta_1 (including)
Windows_2003_serverMicrosoftstandard (including)standard (including)
Windows_2003_serverMicrosoftstandard-sp1_beta_1 (including)standard-sp1_beta_1 (including)
Windows_2003_serverMicrosoftweb (including)web (including)
Windows_2003_serverMicrosoftweb-sp1_beta_1 (including)web-sp1_beta_1 (including)
Windows_ntMicrosoft4.0 (including)4.0 (including)
Windows_ntMicrosoft4.0-sp1 (including)4.0-sp1 (including)
Windows_ntMicrosoft4.0-sp2 (including)4.0-sp2 (including)
Windows_ntMicrosoft4.0-sp3 (including)4.0-sp3 (including)
Windows_ntMicrosoft4.0-sp4 (including)4.0-sp4 (including)
Windows_ntMicrosoft4.0-sp5 (including)4.0-sp5 (including)
Windows_ntMicrosoft4.0-sp6 (including)4.0-sp6 (including)
Windows_ntMicrosoft4.0-sp6a (including)4.0-sp6a (including)
Windows_xpMicrosoft**

References