peter bassill · operator
$ cve CVE-2003-1378 JSON

CVE-2003-1378 EXPLOIT

8.8
HIGH · CVSS 2.0 · EPSS 15.6% (pctl 97)

Patch early

A public exploit exists.

Description

Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.

Scoring

CVSS8.8 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:N
EPSS15.58% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2003-12-31
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftoutlook
microsoftoutlook express

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD