New MSIE Vulnerability - Remote Access
A Microsoft Internet Explorer vulnerability was found by GreyMagic
(http://security.greymagic.com/adv/gm001-ie/). With IncrediMail, it's
possible to gain a remote access on a computer.
Incredimail save automatically email attachements in this directory
(on Windows 2000 Professionnal) :
C:Program
FilesIncrediMailDataIdentities{42D00B20-479C-11d4-9706- 00105A40931C}Message
StoreAttachments
So if you send an html email with the GreyMagic vulnerability and a
trojan in attachments, it will be save in this directory.
The html mail contains this code :
]]>
So, the trojan is executed automatically.