7.5
CVSSv2

CVE-2004-0121

Published: 15/04/2004 Updated: 13/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote malicious users to use script code in the Local Machine zone and execute arbitrary programs.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft outlook 2002

microsoft office xp

Exploits

source: wwwsecurityfocuscom/bid/9827/info Microsoft Outlook is prone to a vulnerability that may permit execution of arbitrary code on client systems This issue is exposed through Outlook, but will reportedly cause Internet Explorer to load malicious content in the Local Zone This is related to how mailto URIs are handled by the softwa ...