No, it's not an OS flaw. The OS MUST allow files to be executed no matter their location. Also because it is very complex for the OS to determine if the file has just been downloaded or not.
This kind of issue pertains more to Safari, which should NOT execute files with a non recognized mimetype but instead prompt the user for their (optional) download.
Like, you know, any other browser.
In reply to: "Microsoft warns of Safari for Windows blended attacks"
June 2, 2008
0 replies