Vulnerability record · CVE-2004-0201 · published 6 August 2004
CVE-2004-0201: Microsoft HTML Help hh.exe heap buffer overflow via crafted CHM file
Avaya · Ip600 Media Servers
The HTML Help program (hh.exe) in multiple Microsoft Windows versions contains a heap-based buffer overflow triggered by a .CHM file with a large length field. Because HTML Help is invoked automatically when a CHM file is opened, a remote attacker can craft a malicious CHM and achieve code execution on the victim's system. This is a distinct flaw from CVE-2003-1041.
Description
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 2.0 base score is 10.0 with network reachability and no authentication, and EPSS is in the 98.7th percentile, though exploitation requires a user to open a crafted CHM file.
What it is
The HTML Help program (hh.exe) in multiple Microsoft Windows versions contains a heap-based buffer overflow triggered by a .CHM file with a large length field. Because HTML Help is invoked automatically when a CHM file is opened, a remote attacker can craft a malicious CHM and achieve code execution on the victim's system. This is a distinct flaw from CVE-2003-1041.
Impact
An attacker who successfully exploits the overflow can execute arbitrary commands with the privileges of the user who opens the CHM file. On typical Windows systems this can lead to full compromise of the host.
Attack surface
The vulnerability is network-reachable (AV:N) with no authentication required (Au:N) and low attack complexity (AC:L) per the CVSS 2.0 vector. It is triggered when a user opens or is induced to open a malicious .CHM file, so some form of user interaction is required in practice.
Exploitation
CVE-2004-0201 is not listed in CISA KEV and no ransomware groups are documented using it. EPSS shows a 30-day exploitation probability of 0.45314 (98.7th percentile), and references include patch and US Government advisory tags, indicating public technical detail and available fixes.
What to do
- Apply the Microsoft security update for MS04-023 (or the corresponding vendor patch) to all affected Windows versions.
- Disable or restrict automatic handling of .CHM files, for example by removing or blocking the HTML Help ActiveX control and hh.exe associations where not required.
- Block .CHM file attachments and downloads at email and web gateways unless explicitly needed for business.
- Educate users not to open CHM files from untrusted sources and enforce attachment filtering policies.
- For Avaya products listed as affected, apply the vendor's corresponding advisory or patch.
Detection
- Monitor for hh.exe spawning child processes such as cmd.exe, powershell.exe, or other unexpected executables.
- Alert on .CHM files written to or executed from user-writable directories such as Downloads, Temp, or email attachment caches.
- Use file integrity monitoring or EDR to detect anomalous hh.exe behavior and heap corruption-related crashes.
- Review proxy and email logs for .CHM file transfers from external or untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0201 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0201), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.