CVE-2002-0823: Microsoft Windows 2000
High severity, CVSS 7.5. EPSS: 26.2% chance of exploitation in the next 30 days.
Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HTML Help ActiveX control (HHCtrl.ocx) with a long pathname in the Item parameter.
Affected products
Published 2002-08-12. Last modified 2026-06-16.