CVE-2008-1585
Apple QuickTime before 7.5 uses the url.dll!FileProtocolHandler handler for unrecognized URIs in qt:next attributes with
Apple QuickTime before 7.5 uses the url.dll!FileProtocolHandler handler for unrecognized URIs in qt:next attributes within SMIL text in video files, which sends these URIs to explorer.exe and thereby allows remote attackers to execute arbitrary programs, as originally demonstrated by crafted file: URLs.
MEDIUM · CVSS 6.8
EPSS 0.08228
Monitor
- EPSS percentile: top 8% of all CVEs by exploitation likelihood
Sigma rules0
YARA rules0