Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-037
No PoCs found on GitHub currently.