CVE-2002-0823: Microsoft Windows 2000

High severity, CVSS 7.5. EPSS: 26.2% chance of exploitation in the next 30 days.

Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HTML Help ActiveX control (HHCtrl.ocx) with a long pathname in the Item parameter.

Affected products

Published 2002-08-12. Last modified 2026-06-16.