cve/2007/CVE-2007-3896.md
2024-05-26 14:27:05 +02:00

18 lines
1.0 KiB
Markdown

### [CVE-2007-3896](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3896)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as demonstrated using mIRC, Outlook, Firefox, Adobe Reader, Skype, and other applications. NOTE: this issue might be related to other issues involving URL handlers in Windows systems, such as CVE-2007-3845. There also might be separate but closely related issues in the applications that are invoked by the handlers.
### POC
#### Reference
- http://www.heise-security.co.uk/news/96982
#### Github
No PoCs found on GitHub currently.