Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1764
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1743
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1679
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1448
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1191
https://exchange.xforce.ibmcloud.com/vulnerabilities/25554
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-015
http://www.vupen.com/english/advisories/2006/1320
http://www.us-cert.gov/cas/techalerts/TA06-101A.html
http://www.securityfocus.com/bid/17464
http://www.kb.cert.org/vuls/id/641460