There is an input validation flaw in Internet Explorer that allows you to specify arbitrary arguments to the process responsible for handling URL protocols.
This is the simplest way to get RCE from a browser that has ever been disclosed. Larholm.com - Me, myself and I ? Internet Explorer 0day Exploit |