@buherator The person reporting this vulnerability has almost certainly stumbled onto URI handlers, which in the right context and program, can get nearly dangerous.
I for one, got cmd.exe to execute, but could not pass any args. It's an infuriating edge case.