CVE Database
/

CVE-2002-0694

Back to search

CVE-2002-0694

Published: Sep 1, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File."

VendorProductVersions

n/a

n/a

affected
n/a

References

MS02-055
vendor-advisory
x_refsource_MS
oval:org.mitre.oval:def:403
vdb-entry
signature
x_refsource_OVAL
win-chm-code-execution(10254)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now