SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2003-1378

Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.

HIGH 8.8EPSS 15.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 15.6%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.

CVSS 2.0
8.8 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:N
EPSS
15.58% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
microsoft/outlook · microsoft/outlook express
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.