SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-3896

The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as…

HIGH 9.3EPSS 53.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 53.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as demonstrated using mIRC, Outlook, Firefox, Adobe Reader, Skype, and other applications. NOTE: this issue might be related to other issues involving URL handlers in Windows systems, such as CVE-2007-3845. There also might be separate but closely related issues in the applications that are invoked by the handlers.

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
53.83% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
microsoft/internet explorer
Source
secure@microsoft.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.