Back

CVE-2003-1378

Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.

Published: Dec 31, 2003 Modified: Jun 16, 2026
CWE-264

CVSS Metrics

Affected Products (4)

Vendor Product Version
microsoft outlook 2000
microsoft outlook 2000
microsoft outlook 2000
microsoft outlook_express 6.0

GitHub Security Advisory GHSA-rx6q-7jmv-mc9j

Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone,...

Risk Scores

CVSS Score 8.8 / 10
EPSS Score 15.58%

Top 3% most likely to be exploited

Threat Score 39.9 / 100

Data Sources

NVD EPSS GitHub