A simple email gives the attackers the ability to remotely inject OS commands.
To respect copyright, we link to the source rather than republishing the full text. Read the complete article on Ars Technica.