# File Download Extension Spoofing in MSIE

**URL:** <https://forum.kirupa.com/t/file-download-extension-spoofing-in-msie/100387>\
**Category:** Uncategorized\
**Created:** [January 28, 2004, 9:44pm UTC](https://forum.kirupa.com/t/file-download-extension-spoofing-in-msie/100387 "2004-01-28T21:44:39Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![955](https://avatars.discourse-cdn.com/v4/letter/9/4bbf92/32.png) [@955](https://forum.kirupa.com/u/955)\
**Post date:** [January 28, 2004, 9:44pm UTC](https://forum.kirupa.com/t/file-download-extension-spoofing-in-msie/100387/1 "2004-01-28T21:44:39Z")

</div>

> **[About Secunia Research | Flexera](https://www.flexera.com/products/security/software-vulnerability-research/secunia-research?referrer=secunia)**
>
> Flexera provides software licensing management, software compliance, installation and application packaging solutions to developers and their customers.

> 

The problem is that Internet Explorer can be tricked into opening a file, with a different application than indicated by the file extension. This can be done by embedding a CLSID in the file name. This could be exploited to trick users into opening “trusted” file types which are in fact malicious files.

when combined with the other hole found earlier, the results wouldn’t be pretty.

Yet another reason not to use IE.
