PT-2007-5144 · Microsoft+1 · Internet Explorer+1

Published

2007-07-21

·

Updated

2021-07-23

·

CVE-2007-3924

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Internet Explorer (affected versions not specified)
Description: The issue allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a -chrome argument to the navigatorurl URI. This occurs when Microsoft Internet Explorer is running on systems with Netscape installed and certain URIs registered. The problem arises because Internet Explorer does not properly delimit the URL argument when invoking netscape.exe, which could also affect other protocol handlers in Internet Explorer.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3924

Affected Products

Internet Explorer
Netscape