peter bassill · operator
$ cve CVE-2004-0121 JSON

CVE-2004-0121 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 47.7% (pctl 99)

Patch early

A public exploit exists.

Description

Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS47.68% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-88
On CISA KEVno
Public exploityes
Published2004-04-15
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftoffice
microsoftoutlook

Public exploits

SourceTitleDate
exploit-dbMicrosoft Outlook 2002 - 'Mailto' Quoting Zone Bypass2004-03-09

References

→ the Explorer  ·  watch your stack  ·  NVD