Untrusted search path vulnerability in XnView before 1.98.1 allows local users to gain privileges via a Trojan horse .exe file in a folder selected by the "Open containing folder" menu item.
https://exchange.xforce.ibmcloud.com/vulnerabilities/68369
http://www.securityfocus.com/bid/48562
http://secunia.com/advisories/45127