Vulnerability record · CVE-2006-0564 · published 6 February 2006
CVE-2006-0564: Microsoft HTML Help Workshop stack buffer overflow via .hhp file
Microsoft · Html Help
Microsoft HTML Help Workshop 4.74.8702.0 (and possibly earlier versions, as shipped in the HTML Help 1.4 SDK) has a stack-based buffer overflow when processing a .hhp project file with an overly long Contents file field. Because the flaw is reachable through a file a user may open, it matters to anyone who compiles or opens untrusted help project files on a system with the vulnerable tooling installed.
Description
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file field.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
medium priorityHigh CVSS and very high EPSS, but exploitation requires a user to open a crafted .hhp file in a legacy authoring tool, and no KEV listing or known in-the-wild use is recorded.
What it is
Microsoft HTML Help Workshop 4.74.8702.0 (and possibly earlier versions, as shipped in the HTML Help 1.4 SDK) has a stack-based buffer overflow when processing a .hhp project file with an overly long Contents file field. Because the flaw is reachable through a file a user may open, it matters to anyone who compiles or opens untrusted help project files on a system with the vulnerable tooling installed.
Impact
An attacker who gets a crafted .hhp file opened can execute arbitrary code in the context of the user running HTML Help Workshop. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.
Attack surface
Reached over the network per the AV:N vector, but exploitation depends on a context-dependent attacker delivering a malicious .hhp file that the victim opens in the vulnerable application; no authentication is required, and user interaction with the file is implied by the description.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high at roughly 0.72 (99th percentile), indicating elevated predicted exploitation activity; references are advisories only, with no public exploit tag.
What to do
- Apply the vendor fix or upgrade to a non-vulnerable build of HTML Help Workshop / HTML Help SDK if one is available; the record does not name a fixed version.
- Restrict or remove HTML Help Workshop and the HTML Help 1.4 SDK from systems that do not require them.
- Block or quarantine untrusted .hhp files at email and web gateways, and warn users not to open help project files from unknown sources.
- Run the tool with least privilege and in a sandbox or isolated VM when handling files of unknown origin.
Detection
- Monitor for HTML Help Workshop (hhw.exe) spawning unexpected child processes such as cmd.exe or scripting hosts after opening a .hhp file.
- Alert on .hhp files arriving via email or download that contain abnormally long Contents file field values.
- Hunt for crashes or access violations in hhw.exe correlated with recent .hhp file opens.
- Track execution of hhw.exe on hosts where the tool is not expected to be used.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-0564 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-0564), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.