Advisories Blog | G5 Cyber Security

win-mailto.txt

Multiple browsers Windows mailto protocol Office 2003 file attachment exploit: Application protocols handling in Microsoft Windows is badly designed, i.e. when someone types mailto:someone@somewhere.com into a browser the protocol is first looked up under HKEY_CLASSES_ROOT%protocol%shellopencommand, if it is a protocol that is allowed under the current user context then the value is simply replaced by the contents in the address bar at %1.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/45815/win-mailto.txt

Source: https://packetstormsecurity.com/files/45815/win-mailto.txt.html

Exit mobile version