[Full-disclosure] Microsoft Windows Help program (WinHlp32.exe) memory corruption

2012-10-27 Thread kaveh ghaemmaghami
Hello list! I want to warn you about Microsoft Windows Help program (WinHlp32.exe) memory corruption Best Regards Kaveh Ghaemmaghami aka (coolkaveh) -

Re: [Full-disclosure] Microsoft Windows Help program (WinHlp32.exe) memory corruption

2012-10-27 Thread Gynvael Coldwind
Hi Kaveh, Mario has a point. Why do you care about any bug in winhlp if by design you can embed a DLL file in the .hlp file and run arbitrary code? See e.g. Wikipedia http://en.wikipedia.org/wiki/WinHelp#WinHelp_appearance_and_features: A rather security critical feature is that one can also