A vulnerability was reported in Windows XP SP2 in the display of files within zip archives. Windows Explorer and Microsoft Internet Explorer may display a file with the wrong icon.

http-equiv reported that a remote user can create a zip archive containing a malicious file so that when the archived is viewed using Windows XP SP2's native Explorer or Internet Explorer archive viewing functionality, the file will show an arbitrary icon.

Michael Young of Miles Technologies subsequently reported that the regedit.exe, winhelp.exe, and explorer.exe filenames will also display their corresponding icon.

View:
More Information