April 20, 2001

Windows class IDs create vulnerability

Author: JT Smith

MSNBC: "Windows users also having
problems distinguishing between good and bad applications. As
security analyst Georgi Guninski has recently shown, malicious
users can play a devastating trick on Windows systems using a
CLSID extension, and thereby disguise a potentially dangerous
COM object as a lowly .TXT file."
