CVE-2003-1041
published 2004-06-14CVE-2003-1041: Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot…
PriorityP267high7.5CVSS 2.0
AVNACLAuNCPIPAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
52.61%
98.8th percentile
Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CVE-2004-0475.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avaya | modular_messaging_message_storage_server | — | — |
| microsoft | ie | — | — |
| microsoft | ie | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_nt | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for use of the mk:@MSITStore: URI protocol handler combined with directory traversal sequences (e.g., ..\..\) in showHelp() calls, which is the core bypass technique for CVE-2003-1041. ↗
- →Treat Internet Explorer, Outlook, and Outlook Express as attack surface vectors for this vulnerability — monitor for CHM file loads originating from these processes. ↗
- →Flag any web page or email invoking showHelp() with a mk:@MSITStore: reference pointing to a local .CHM file, as this is the exploitation pattern described in MS03-004. ↗
- ·CVE-2003-1041 is explicitly a different vulnerability from CVE-2004-0201 (heap overflow in hh.exe); do not conflate the two — CVE-2003-1041 is the showHelp() directory traversal bypass, not the large length field heap overflow. ↗
- ·This issue was initially misattributed to Internet Explorer alone; it is an OS-level flaw, meaning patching IE is insufficient — the underlying Windows showHelp/CHM handling must be patched. ↗
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q48v-h8j7-56w2: Internet Explorer 5
ghsa_unreviewed·2022-04-29·CVSS 5.1
CVE-2003-1041 [MEDIUM] GHSA-q48v-h8j7-56w2: Internet Explorer 5
Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CVE-2004-0475.
GHSA
GHSA-624v-gqcq-xp7r: The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute arbitrary local
ghsa_unreviewed·2022-04-29·CVSS 7.5
CVE-2004-0475 [HIGH] GHSA-624v-gqcq-xp7r: The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute arbitrary local
The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute arbitrary local .CHM files via a double backward slash ("\\") before the target CHM file, as demonstrated using an "ms-its" URL to ntshared.chm. NOTE: this bug may overlap CVE-2003-1041.
GHSA
GHSA-rfqx-p859-5rqq: Heap-based buffer overflow in the HtmlHelp program (hh
ghsa_unreviewed·2022-04-29·CVSS 7.5
CVE-2004-0201 [HIGH] GHSA-rfqx-p859-5rqq: Heap-based buffer overflow in the HtmlHelp program (hh
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
VulnCheck
Microsoft Internet Explorer Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulncheck·2003·CVSS 7.5
CVE-2003-1041 [HIGH] Microsoft Internet Explorer Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Microsoft Internet Explorer Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CVE-2004-0475.
Affected: Microsoft Internet Explorer
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-023
No detection rules found.
No writeups or analysis indexed.
http://www.kb.cert.org/vuls/id/187196http://www.securityfocus.com/archive/1/348521http://www.securityfocus.com/bid/9320http://www.us-cert.gov/cas/techalerts/TA04-196A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-023https://exchange.xforce.ibmcloud.com/vulnerabilities/14105https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1186https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1943https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3514https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A956http://www.kb.cert.org/vuls/id/187196http://www.securityfocus.com/archive/1/348521http://www.securityfocus.com/bid/9320http://www.us-cert.gov/cas/techalerts/TA04-196A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-023https://exchange.xforce.ibmcloud.com/vulnerabilities/14105https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1186https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1943https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3514https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A956
2004-06-14
Published
Exploited in the wild