CVE-2004-2289
Microsoft Windows XP Explorer allows local users to execute arbitrary code via a system folder with a Desktop.ini file containing a .ShellClassInfo specifier with a CLSID value that is associated with an executable file.
Date published : 2005-08-04
http://www.securityfocus.com/bid/10363
http://archives.neohapsis.com/archives/bugtraq/2004-05/0168.html