Vulnerability record · CVE-2009-0133 · published 15 January 2009
CVE-2009-0133: Microsoft HTML Help Workshop buffer overflow via long Index file field
Microsoft · Html Help Workshop
Microsoft HTML Help Workshop 4.74 and earlier contains a buffer overflow (CWE-119) triggered by a .hhp project file containing an overly long "Index file" field. The flaw is described as context-dependent, meaning exploitation depends on how the crafted file is opened or processed. It matters because successful exploitation allows arbitrary code execution on the affected system.
Description
Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityFull-impact remote code execution with public exploit code and very high EPSS, though it requires a crafted file to be opened and no fixed version is stated in the record.
What it is
Microsoft HTML Help Workshop 4.74 and earlier contains a buffer overflow (CWE-119) triggered by a .hhp project file containing an overly long "Index file" field. The flaw is described as context-dependent, meaning exploitation depends on how the crafted file is opened or processed. It matters because successful exploitation allows arbitrary code execution on the affected system.
Impact
An attacker who gets a crafted .hhp file processed can execute arbitrary code in the context of the user or process handling the file. The CVSS 2.0 vector rates full confidentiality, integrity and availability impact.
Attack surface
The vector is network-reachable (AV:N) with no authentication required (Au:N) and low complexity (AC:L), but the description says context-dependent attackers, so a crafted .hhp file must be delivered and opened or processed by the victim. User interaction is implied by the file-based delivery, though the record does not state it explicitly.
Exploitation
CVE-2009-0133 is not listed in CISA KEV and no ransomware use is documented, but EPSS is high at 0.67049 (99.3rd percentile) and public Exploit-DB references exist, indicating known exploit code is available.
What to do
- Apply the vendor fix or upgrade HTML Help Workshop beyond version 4.74 if a patched release exists; the record does not name a fixed version.
- Block or restrict opening of untrusted .hhp project files, especially from email or downloads.
- Enforce least privilege so code execution from a help-authoring tool does not run with administrative rights.
- Use application allowlisting or file-type controls to prevent unauthorized .hhp handling on authoring workstations.
Detection
- Monitor for HTML Help Workshop processes spawning unexpected child processes such as cmd.exe or powershell.exe.
- Alert on .hhp files arriving via email or web download and subsequently opened by the help compiler.
- Hunt for crash or exception events in hhw.exe or related binaries tied to malformed .hhp input.
- Review endpoint telemetry for code execution originating from the HTML Help Workshop install directory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-0133 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-0133), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.