>> Microsoft Windows URI Handler Command Execution Vulnerability (MS07-061)
Title : Microsoft Windows URI Handler Command Execution Vulnerability (MS07-061) VUPEN ID : VUPEN/ADV-2007-2668 CVE ID : CVE-2007-3896 - CVE-2007-3924 - CVE-2007-4042
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-26
Technical Description
A vulnerability has been identified in Microsoft Windows, which could be exploited by attackers to take complete control of an affected system with MS Internet Explorer 7 installed. This issue is caused by an input validation error when processing specially crafted arguments passed to certain registered URI handlers (e.g. "mailto:"), which could be exploited by remote attackers to inject and execute arbitrary commands by tricking a user into visiting a specially crafted web page using a vulnerable application (e.g. Netscape or mIRC).