winpm-32.exe in Pegasus Mail (aka Pmail) v4.72 build 572 allows code execution via a crafted ssgp.dll file that must be installed locally. For example, if ssgp.dll is on the desktop and executes arbitrary code in the DllMain function, then clicking on a mailto: link on a remote web page triggers the attack.
2017-05-21T14:29:00.260
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.3 (HIGH)
AV:L/AC:M/Au:N/C:P/I:P/A:P
3.4
6.4