Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2007-3896 Details

Description

The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as demonstrated using mIRC, Outlook, Firefox, Adobe Reader, Skype, and other applications. NOTE: this issue might be related to other issues involving URL handlers in Windows systems, such as CVE-2007-3845. There also might be separate but closely related issues in the applications that are invoked by the handlers.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://blogs.zdnet.com/security/?p=577 CVE
http://marc.info/?l=bugtraq&m=119143780202107&w=2 CVE
http://marc.info/?l=bugtraq&m=119144449915918&w=2 CVE
http://marc.info/?l=bugtraq&m=119159924712561&w=2 CVE
http://marc.info/?l=bugtraq&m=119168062128026&w=2 CVE

see all 80 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-20Improper Input Validation[email protected]

Affected Products

ProductVersions
microsoft windows 2003 server
All versions

CPE

  • cpe:2.3:o:microsoft:windows_2003_server:*:*:itanium:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_2003_server:*:*:x64:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_2003_server:*:sp2:itanium:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:*

Remediation

  • No remediation found in references.
microsoft windows xp
All versions

CPE

  • cpe:2.3:o:microsoft:windows_xp:*:*:x64:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_xp:*:sp2:x64:*:*:*:*:*

Remediation

  • No remediation found in references.
microsoft internet explorer
7.0

CPE

  • cpe:2.3:a:microsoft:internet_explorer:7.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

9 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2007-3896
NVD Published Date:
Oct 11, 2007
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2007-3896 Details - Not Deferred