CVE-2006-0564 is a stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, including the copy distributed with the Microsoft HTML Help 1.4 SDK. The flaw is caused by insufficient validation of the Contents file field in the header of an HTML Help Workshop Project (.hhp) file. When a user opens a specially crafted .hhp project file containing an overly long value in that field, the application can overflow a stack buffer, potentially allowing attacker-controlled code execution in the context of the user running the application. Public exploit code was reported as available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (6 hidden).
This repository contains a single Metasploit module targeting a stack buffer overflow vulnerability (CVE-2006-0564) in Microsoft HTML Help Workshop 4.74 (hhw.exe v4.74.8702.0) on Windows XP SP3. The exploit works by generating a specially crafted .hhp project file (default name: msf.hhp) that, when opened by the vulnerable application, triggers a buffer overflow and executes arbitrary code. The module uses Metasploit's egghunter technique to deliver the payload, which can be any Metasploit-compatible shellcode up to 1024 bytes, avoiding certain bad characters. The attack vector is local, requiring user interaction to open the malicious file. The repository is structured as a single Ruby file within the Metasploit framework, leveraging its file format and egghunter exploit mixins. No network endpoints are involved; the main fingerprintable artifacts are the malicious .hhp file and the target application (hhw.exe).
This repository contains a single Metasploit module targeting a stack buffer overflow vulnerability (CVE-2006-0564) in Microsoft HTML Help Workshop 4.74 (specifically hhw.exe v4.74.8702.0) on Windows XP SP3. The exploit works by generating a specially crafted .hhp (HTML Help Project) file that, when opened by the vulnerable application, triggers a buffer overflow and executes arbitrary code supplied as a payload. The module uses Metasploit's egghunter technique to locate the payload in memory and allows the attacker to specify the payload type (e.g., reverse shell, meterpreter). The only fingerprintable endpoint is the malicious .hhp file itself, which is created as 'msf.hhp' by default. The exploit is operational and requires user interaction (the victim must open the file). The code is written in Ruby and is structured as a standard Metasploit exploit module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.