IE / Outlook / MS SHLWAPI Render - more trivial crash

From: Ramon Pinuaga Cascales (
Date: 04/22/03

  • Next message: KF: "SRT2003-04-22-1336 - SAP DB Development Tools install flaw"
    Date: Tue, 22 Apr 2003 00:07:20 +0200
    From: Ramon Pinuaga Cascales <>


    Well, as it seems that is the Microsoft Crash mounth, let see another one:


    <input type crash>


    This will crash IE with the following error:

    "Unhandled exception in iexplore.exe (SHLWAPI.DLL): 0xC0000005: Access

    It's a null pointer overwrite, so it's not easly exploitable...

    This HTML also crash Outlook, Frontpage, and all the Microsoft
    programs that use the shlwapi.dll library to render web code.

    Plain HTML is a dangerous language :)

     Ramon Pinuaga Cascales  
     Analista de Seguridad Telematica
     Tfno: 620921960

  • Next message: KF: "SRT2003-04-22-1336 - SAP DB Development Tools install flaw"

    Relevant Pages

    • IE Immediately Crashes When Loading A HTML Page From A CD/DVD
      ... The CSS files just reference the images ... When I load index.html from my hard drive, IE displays the page fine, ... the Autorun.inf and HTML directory to a CD (using either Nero or the ... before you even see anything of the page, IE will crash. ...
    • Re:
      ... > I have created an order form that users javascript to create a new html ... > document when the customers clicks the "print page" button. ... My testing in Firefox 1.5 seems to indicate that window.print is ... pretty obvious that no matter what, it shouldn't be able to crash the ...
    • Re: MS Pocket IE team or Jay McLain: can you help?
      ... > This seems to be a bug with Html View in Pocket PC 2003 because I can ... The problem is with sending HTML to a Html ... As soon as DTM_ENDOFSOURCE is sent, the control ... > stable with less crash. ...
    • Re: FireFox bugged isolated
      ... you're saying if someone wrote some malicious HTML that will cause ... > Firefox to freeze or crash then no part of Firefox's code can be blamed? ... for Microsoft trying to change HTML into crap and then using illegal methods ...
    • Re: Need help with making a link bar float
      ... I should probably also tell you that I have no clue how to use html. ... "Rob Giordano (Crash)" wrote: ...