Multiple browsers Windows mailto protocol Office 2003 file attachment exploit: Application protocols handling in Microsoft Windows is badly designed, i.e. when someone types mailto:someone@somewhere.com into a browser the protocol is first looked up under HKEY_CLASSES_ROOT%protocol%shellopencommand, if it is a protocol that is allowed under the current user context then the value is simply replaced by the contents in the address bar at %1.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/45815/win-mailto.txt
Source: https://packetstormsecurity.com/files/45815/win-mailto.txt.html