8.8
CVSSv2

CVE-2003-1378

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 8.8 | Impact Score: 9.2 | Exploitability Score: 8.6
VMScore: 885
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:N

Vulnerability Summary

Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote malicious users to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft outlook 2000

microsoft outlook express 6.0

Exploits

source: wwwsecurityfocuscom/bid/6923/info Microsoft Outlook and Outlook Express may execute arbitrary programs through objects embedded in HTML email messages When an email message or newsgroup message is viewed using Outlook, a temporary object is created in the Internet Explorer cache The security zone of this cache should be set by I ...