HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This vulnerability has a 35.31% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.