The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as demonstrated using mIRC, Outlook, Firefox, Adobe Reader, Skype, and other applications. NOTE: this issue might be related to other issues involving URL handlers in Windows systems, such as CVE-2007-3845. There also might be separate but closely related issues in the applications that are invoked by the handlers.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://blogs.zdnet.com/security/?p=577 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=119143780202107&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=119144449915918&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=119159924712561&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=119168062128026&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=119194714125580&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=119195904813505&w=2 cve-icon cve-icon
http://marc.info/?l=full-disclosure&m=119159477404263&w=2 cve-icon cve-icon
http://marc.info/?l=full-disclosure&m=119168727402084&w=2 cve-icon cve-icon
http://marc.info/?l=full-disclosure&m=119170531020020&w=2 cve-icon cve-icon
http://marc.info/?l=full-disclosure&m=119171444628628&w=2 cve-icon cve-icon
http://marc.info/?l=full-disclosure&m=119175323322021&w=2 cve-icon cve-icon
http://marc.info/?l=full-disclosure&m=119180333805950&w=2 cve-icon cve-icon
http://secunia.com/advisories/26201 cve-icon cve-icon
http://securitytracker.com/id?1018831 cve-icon cve-icon
http://www.heise-security.co.uk/news/96982 cve-icon cve-icon
http://www.kb.cert.org/vuls/id/403150 cve-icon cve-icon
http://www.microsoft.com/technet/security/advisory/943521.mspx cve-icon cve-icon
http://www.securityfocus.com/archive/1/481493/100/100/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481505/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481624/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481664/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481671/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481680/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481839/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481846/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481867/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481871/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481881/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481887/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/482090/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/482292/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/482437/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/484186/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/25945 cve-icon cve-icon
http://www.securitytracker.com/id?1018822 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA07-317A.html cve-icon cve-icon
http://xs-sniper.com/blog/remote-command-exec-firefox-2005/ cve-icon cve-icon
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-061 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4581 cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2024-08-07T14:37:04.553Z

Reserved: 2007-07-19T00:00:00

Link: CVE-2007-3896

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2007-10-11T00:17:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2007-3896

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.