Actually I've never understood why autorun should be considered a vulnerability?
Because it's a very simple matter to drop malware via Autoplay. This is why most responsible organisations disable it or even disable access to media which can be automatically run.
Many schools and places likew PC World etc have been plagued by 12 year olds with pen drives infecting machines of all sorts. This is why it's essential to run a full offline scan on any chain bought machine.
Edit: I'll see your edit and raise you.
Edited by Deadbeat (Sat 28-Apr-12 17:43:57)