Privacy and Legal Notice

CIAC INFORMATION BULLETIN

Q-272: Vulnerability in HTML Help

[Microsoft Security Bulletin MS06-046 (922616)]

August 8, 2006 20:00 GMT
[REVISED 02 Nov 2006]
[REVISED 5 Dec 2006]

PROBLEM: A vulnerability exists in the HTML Help ActiveX Control.
PLATFORM: • Microsoft Windows 2000 Service Pack 4
• Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2
• Microsoft Windows XP Professional x64 Edition
• Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1
• Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
• Microsoft Windows Server 2003 x64 Edition
HP-UX B.11.00, B.11.11, B.11.23
DAMAGE: Remote code execution.
SOLUTION: Upgrade to the appropriate version.

VULNERABILITY
ASSESSMENT:
The risk is HIGH. Could allow remote code execution on an affected system.

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/q-272.shtml
  ORIGINAL BULLETIN: Microsoft Security Bulletin MS06-046 (922616)
http://www.microsoft.com/technet/security/bulletin/ms06-046.mspx
Visit Hewlett-Packard Subscription Service for:
HPSBUX02164 SSRT061265
Visit Hewlett-Packard Subscription Service for:
HPSBUX02172 SSRT061269
Visit Hewlett-Packard Subscription Service for:
HPSBUX02145 SSRT061202 rev. 2
  CVE: CVE-2006-3357

   REVISION HISTORY:
11/02/2006 - added links to HPSBUX02164 SSRT061265 and HPSBUX02172 SSRT061269
12/05/2006 - revised to add link to HPSBUX02145 SSRT061202 for HP-UX 
             B.11.00, B.11.11, B.11.23.


[***** Start Microsoft Security Bulletin MS06-046 (922616) *****]



Microsoft Security Bulletin MS06-046

Vulnerability in HTML Help Could Allow Remote Code Execution (922616)

Published: August 8, 2006

Version: 1.0

Summary

Who Should Read this Document: Customers who use Microsoft Windows

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Customers should apply the update immediately.

Security Update Replacement: This bulletin replaces a prior security update. See the frequently asked questions (FAQ) section of this bulletin for the complete list.

Caveats: None.

Tested Software and Security Update Download Locations:

Affected Software:

Microsoft Windows 2000 Service Pack 4 — Download the update

Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2 — Download the update

Microsoft Windows XP Professional x64 Edition — Download the update

Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1 — Download the update

Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems — Download the update

Microsoft Windows Server 2003 x64 Edition — Download the update

Top of sectionTop of section

The software in this list has been tested to determine whether the versions are affected. Other versions either no longer include security update support or may not be affected. To determine the support life cycle for your product and version, visit the Microsoft Support Lifecycle Web site

Note The security updates for Microsoft Windows Server 2003, Windows Server 2003 Service Pack 1, and Windows Server 2003 x64 Edition also apply to Windows Server 2003 R2.

General Information

Executive Summary

Executive Summary:

This update resolves a newly discovered, publicly reported vulnerability as well as additional issues discovered through internal investigations. The vulnerability is documented in the "Vulnerability Details" section of this bulletin.

On vulnerable versions of Windows, if a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of the client workstation. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

We recommend that customers apply the update immediately.

Severity Ratings and Vulnerability Identifiers:

Vulnerability Identifiers Impact of Vulnerability Windows 2000 Windows XP Service Pack 1 Windows XP Service Pack 2 Windows Server 2003 Windows Server 2003 Service Pack 1

Buffer Overrun in HTML Help Vulnerability - CVE-2006-3357

Remote Code Execution

Critical

Critical

Critical

Moderate

Moderate

This assessment is based on the types of systems that are affected by the vulnerability, their typical deployment patterns, and the effect that exploiting the vulnerability would have on them.

Note By default, Internet Explorer on Windows Server 2003 runs in a restricted mode that is known as Enhanced Security Configuration. This mode mitigates some of the vulnerabilities. See the FAQ section for this security update for more information about Internet Explorer Enhanced Security Configuration.

Note The security updates for Microsoft Windows Server 2003, Windows Server 2003 Service Pack 1, and Windows Server 2003 x64 Edition also apply to Windows Server 2003 R2.

Note The severity ratings for non-x86 operating system versions map to the x86 operating systems versions as follows:

The Microsoft Windows XP Professional x64 Edition severity rating is the same as the Windows XP Service Pack 2 severity rating.

The Microsoft Windows Server 2003 for Itanium-based Systems severity rating is the same as the Windows Server 2003 severity rating.

The Microsoft Windows Server 2003 with SP1 for Itanium-based Systems severity rating is the same as the Windows Server 2003 Service Pack 1 severity rating.

The Microsoft Windows Server 2003 x64 Edition severity rating is the same as the Windows Server 2003 Service Pack 1 severity rating.

Frequently Asked Questions (FAQ) Related to This Security Update

Vulnerability Details

Buffer Overrun in HTML Help Vulnerability - CVE-2006-3357

Security Update Information

Affected Software:

For information about the specific security update for your affected software, click the appropriate link:

Windows Server 2003 (all versions)

Windows XP (all versions)