← Vulnerability feed

Vulnerability record · CVE-2004-0201 · published 6 August 2004

CVE-2004-0201: Microsoft HTML Help hh.exe heap buffer overflow via crafted CHM file

Avaya · Ip600 Media Servers

The HTML Help program (hh.exe) in multiple Microsoft Windows versions contains a heap-based buffer overflow triggered by a .CHM file with a large length field. Because HTML Help is invoked automatically when a CHM file is opened, a remote attacker can craft a malicious CHM and achieve code execution on the victim's system. This is a distinct flaw from CVE-2003-1041.

10.0 CVSS 2.0 High EPSS 45% · top 1.2%
10.0CVSS 2.0 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityCVSS 2.0 base score is 10.0 with network reachability and no authentication, and EPSS is in the 98.7th percentile, though exploitation requires a user to open a crafted CHM file.

What it is

The HTML Help program (hh.exe) in multiple Microsoft Windows versions contains a heap-based buffer overflow triggered by a .CHM file with a large length field. Because HTML Help is invoked automatically when a CHM file is opened, a remote attacker can craft a malicious CHM and achieve code execution on the victim's system. This is a distinct flaw from CVE-2003-1041.

Impact

An attacker who successfully exploits the overflow can execute arbitrary commands with the privileges of the user who opens the CHM file. On typical Windows systems this can lead to full compromise of the host.

Attack surface

The vulnerability is network-reachable (AV:N) with no authentication required (Au:N) and low attack complexity (AC:L) per the CVSS 2.0 vector. It is triggered when a user opens or is induced to open a malicious .CHM file, so some form of user interaction is required in practice.

Exploitation

CVE-2004-0201 is not listed in CISA KEV and no ransomware groups are documented using it. EPSS shows a 30-day exploitation probability of 0.45314 (98.7th percentile), and references include patch and US Government advisory tags, indicating public technical detail and available fixes.

What to do

  • Apply the Microsoft security update for MS04-023 (or the corresponding vendor patch) to all affected Windows versions.
  • Disable or restrict automatic handling of .CHM files, for example by removing or blocking the HTML Help ActiveX control and hh.exe associations where not required.
  • Block .CHM file attachments and downloads at email and web gateways unless explicitly needed for business.
  • Educate users not to open CHM files from untrusted sources and enforce attachment filtering policies.
  • For Avaya products listed as affected, apply the vendor's corresponding advisory or patch.

Detection

  • Monitor for hh.exe spawning child processes such as cmd.exe, powershell.exe, or other unexpected executables.
  • Alert on .CHM files written to or executed from user-writable directories such as Downloads, Temp, or email attachment caches.
  • Use file integrity monitoring or EDR to detect anomalous hh.exe behavior and heap corruption-related crashes.
  • Review proxy and email logs for .CHM file transfers from external or untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023919.html
http://www.kb.cert.org/vuls/id/920060 PatchThird Party AdvisoryUS Government Resource
http://www.us-cert.gov/cas/techalerts/TA04-196A.html PatchThird Party AdvisoryUS Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-023
https://exchange.xforce.ibmcloud.com/vulnerabilities/16586
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1503
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1530
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2155
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3179
http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023919.html
http://www.kb.cert.org/vuls/id/920060 PatchThird Party AdvisoryUS Government Resource
http://www.us-cert.gov/cas/techalerts/TA04-196A.html PatchThird Party AdvisoryUS Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-023
https://exchange.xforce.ibmcloud.com/vulnerabilities/16586
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1503
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1530
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2155
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3179

Track CVE-2004-0201 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2009-1537Microsoft DirectShow QuickTime Parser NULL Byte Overwrite RCEThe QuickTime Movie Parser Filter in quartz.dll (DirectShow, DirectX 7.0 through 9.0c) contains an unspecified NULL byte overwrite flaw. A crafted Qu…KEVEPSS 51%analysed7.8CVE-2010-0232Windows kernel exception handler privilege escalation via NTVDMThe Windows kernel fails to properly validate certain BIOS calls when 16-bit application support is enabled on 32-bit x86 systems. A local user can c…KEVEPSS 29%analysed7.8CVE-2009-1123Microsoft Windows kernel improper validation allows local privilege escalationThe Windows kernel fails to properly validate changes to unspecified kernel objects, letting a local user elevate privileges through a crafted applic…KEVEPSS 4.9%analysed7.8CVE-2004-0210Microsoft Windows POSIX component buffer overflow allows local code executionThe POSIX subsystem in Windows NT and Windows 2000 contains a classic buffer overflow (CWE-120) that can be triggered by local users through crafted …KEVEPSS 7.2%analysed7.8CVE-2002-0367Windows NT/2000 smss.exe debugging subsystem privilege escalationThe smss.exe debugging subsystem in Windows NT and Windows 2000 fails to properly authenticate programs that connect to other programs, allowing a lo…KEVEPSS 4.9%analysed10.0CVE-2010-0269Microsoft windows 7 vulnerabilityThe SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 …EPSS 28%10.0CVE-2010-0231Microsoft windows 2000 permissions and access controls vulnerabilityThe SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1,…EPSS 41%

Source: NIST National Vulnerability Database (record CVE-2004-0201), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.