CVE-2003-1378 EXPLOIT
8.8
HIGH · CVSS 2.0 · EPSS 15.6% (pctl 97)
Patch early
A public exploit exists.
Description
Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.
Scoring
| CVSS | 8.8 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:N |
| EPSS | 15.58% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-12-31 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | outlook |
| microsoft | outlook express |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Outlook2000/Express 6.0 - Arbitrary Program Execution | 2003-02-24 |
References
- http://www.securityfocus.com/archive/1/312910
- http://www.securityfocus.com/archive/1/312929
- http://www.securityfocus.com/bid/6923
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11411
- http://www.securityfocus.com/archive/1/312910
- http://www.securityfocus.com/archive/1/312929
- http://www.securityfocus.com/bid/6923
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11411
→ the Explorer · watch your stack · NVD