The Windows Search component in Microsoft Windows Vista Gold and SP1 and Server 2008 does not properly free memory during a save operation for a Windows Search file, which allows remote attackers to execute arbitrary code via a crafted saved-search file, aka "Windows Saved Search Vulnerability." http://www.microsoft.com/technet/security/Bulletin/MS08-075.mspx
Windows Saved Search Vulnerability - CVE-2008-4268
A remote code execution vulnerability exists when saving a specially crafted search file within Windows Explorer. This operation causes Windows Explorer to exit and restart in an exploitable manner.
Publication date: Wed, 10 Dec 2008 20:00:00 +0000