Description
The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as demonstrated using mIRC, Outlook, Firefox, Adobe Reader, Skype, and other applications. NOTE: this issue might be related to other issues involving URL handlers in Windows systems, such as CVE-2007-3845. There also might be separate but closely related issues in the applications that are invoked by the handlers.
Published: 2007-10-11
Score: 9.3 Critical
EPSS: 83.5% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
http://blogs.zdnet.com/security/?p=577 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=119143780202107&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=119144449915918&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=119159924712561&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=119168062128026&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=119194714125580&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=119195904813505&w=2 cve-icon cve-icon
http://marc.info/?l=full-disclosure&m=119159477404263&w=2 cve-icon cve-icon
http://marc.info/?l=full-disclosure&m=119168727402084&w=2 cve-icon cve-icon
http://marc.info/?l=full-disclosure&m=119170531020020&w=2 cve-icon cve-icon
http://marc.info/?l=full-disclosure&m=119171444628628&w=2 cve-icon cve-icon
http://marc.info/?l=full-disclosure&m=119175323322021&w=2 cve-icon cve-icon
http://marc.info/?l=full-disclosure&m=119180333805950&w=2 cve-icon cve-icon
http://secunia.com/advisories/26201 cve-icon cve-icon
http://securitytracker.com/id?1018831 cve-icon cve-icon
http://www.heise-security.co.uk/news/96982 cve-icon cve-icon
http://www.kb.cert.org/vuls/id/403150 cve-icon cve-icon
http://www.microsoft.com/technet/security/advisory/943521.mspx cve-icon cve-icon
http://www.securityfocus.com/archive/1/481493/100/100/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481505/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481624/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481664/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481671/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481680/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481839/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481846/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481867/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481871/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481881/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/481887/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/482090/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/482292/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/482437/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/484186/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/25945 cve-icon cve-icon
http://www.securitytracker.com/id?1018822 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA07-317A.html cve-icon cve-icon
http://xs-sniper.com/blog/remote-command-exec-firefox-2005/ cve-icon cve-icon
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-061 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4581 cve-icon cve-icon
History

No history.

Subscriptions

Microsoft Internet Explorer Windows 2003 Server Windows Xp
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2024-08-07T14:37:04.553Z

Reserved: 2007-07-19T00:00:00.000Z

Link: CVE-2007-3896

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-10-11T00:17:00.000

Modified: 2026-04-23T00:35:47.467

Link: CVE-2007-3896

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses