Skip to main content

Special Announcement

  • 25 Jun 2024

    Announcement for Change of Chinese Name

    Please note that the Chinese name of HKCERT is changed from 「香港電腦保安事故協調中心」 to 「香港網絡安全事故協調中心」 with immediate effect.

    The English name, abbreviation, web address and email address remained unchanged.

GoogleApps "googleapps.url.mailto:" Argument Injection Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 5 Oct 2009 4662 Views

RISK: Medium Risk

A vulnerability has been identified in Google Apps, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the "googleapps.exe"application when processing parameters passed to the "---renderer-path" argument via the"googleapps.url.mailto:" URI, which could allow attackers to load an execute a malicious binary (e.g. bat or exe file) from a remote location (e.g. network share) by tricking a user into visiting a specially crafted web page, leading to arbitrary code execution.


  • Remote Code Execution

System / Technologies affected

  • Google Apps versions 1.x


There is no patch available for this vulnerability currently.


  • Do not visit untrusted websites or follow untrusted links.

  • Vulnerability Identifier

    • No CVE information is available


    Related Link