10
CVSSv2

CVE-2004-0380

Published: 04/05/2004 Updated: 12/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote malicious users to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft outlook express 5.5

microsoft outlook express 6.0

Exploits

source: wwwsecurityfocuscom/bid/9105/info A vulnerability has been discovered in Microsoft Outlook Express when handling MHTML file and res URIs that could lead to an unexpected file being downloaded and executed The problem occurs due to the component failing to securely handle MHTML file URIs that reference a non-existent resource ...
source: wwwsecurityfocuscom/bid/9105/info A vulnerability has been discovered in Microsoft Outlook Express when handling MHTML file and res URIs that could lead to an unexpected file being downloaded and executed The problem occurs due to the component failing to securely handle MHTML file URIs that reference a non-existent resource Th ...
source: wwwsecurityfocuscom/bid/9658/info Microsoft Internet Explorer has been reported prone to a vulnerability that may permit hostile content to be interpreted in the Local Zone The issue may be exploited via the ITS (InfoTech Storage) Protocol URI handler It is possible to use this protocol to force a browser into the Local Zone b ...