Back

CVE-2004-0121

Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.

Published: Apr 15, 2004 Modified: Jun 16, 2026
CWE-88

CVSS Metrics

Affected Products (2)

Vendor Product Version
microsoft office xp
microsoft outlook 2002

GitHub Security Advisory GHSA-88qv-6q9j-fhvv

Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 47.68%

Top 1% most likely to be exploited

Threat Score 44.3 / 100

Data Sources

NVD EPSS GitHub