The fsmsh.dll host module in F-Secure Policy Manager Server 7.00 and earlier allows remote attackers to cause a denial of service (application crash) via NTFS reserved words in filenames in URLs.
https://exchange.xforce.ibmcloud.com/vulnerabilities/34584
http://www.vupen.com/english/advisories/2007/1986
http://www.securitytracker.com/id?1018149
http://www.securityfocus.com/bid/24233
http://www.f-secure.com/security/fsc-2007-4.shtml