SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-2694

Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook context, and facilitate phishing attacks via a "BASE HREF" with the target set to "_top".

MEDIUM 5.8EPSS 8.56%

Does this matter?

Lower severity and a low EPSS score (8.56%). Track it; it rarely justifies an emergency change on its own.

Description

Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook context, and facilitate phishing attacks via a "BASE HREF" with the target set to "_top".

CVSS 2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS
8.56% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
microsoft/outlook express
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.