CVE-2004-0121
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 47.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 47.68% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-88
- Affected
- microsoft/office · microsoft/outlook
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=107893704602842&w=2Third Party Advisory
- http://www.ciac.org/ciac/bulletins/o-096.shtmlBroken Link
- http://www.idefense.com/application/poi/display?id=79&type=vulnerabilitiesBroken Link, Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/305206Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/9827Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-070A.htmlBroken Link, Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-009Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15414Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15429Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A843Broken Link
- http://marc.info/?l=bugtraq&m=107893704602842&w=2Third Party Advisory
- http://www.ciac.org/ciac/bulletins/o-096.shtmlBroken Link
- http://www.idefense.com/application/poi/display?id=79&type=vulnerabilitiesBroken Link, Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/305206Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/9827Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-070A.htmlBroken Link, Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-009Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15414Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15429Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A843Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.