CVE-2004-0121
Last modified
CVE-2004-0121 is a vulnerability of currently unknown severity. Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.. EPSS estimates a 47.68% chance of exploitation in the next 30 days.
Description
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Office | xp | Sp2 |
| Microsoft | Outlook | 2002 | Sp2 |
References
- http://marc.info/?l=bugtraq&m=107893704602842&w=2Third Party Advisory
- http://www.idefense.com/application/poi/display?id=79&type=vulnerabilitiesBroken Link, Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/305206Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/9827Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-070A.htmlBroken Link, Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-009Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15414Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15429Third Party Advisory, VDB Entry
- http://marc.info/?l=bugtraq&m=107893704602842&w=2Third Party Advisory
- http://www.idefense.com/application/poi/display?id=79&type=vulnerabilitiesBroken Link, Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/305206Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/9827Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-070A.htmlBroken Link, Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-009Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15414Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15429Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0121?
How severe is CVE-2004-0121?
How do I fix CVE-2004-0121?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-0115VirtualPC_Services in Microsoft Virtual PC for Mac 6.0 throu…
- CVE-2004-0116An Activation function in the RPCSS Service involved with DC…
- CVE-2004-0117Unknown vulnerability in the H.323 protocol implementation i…
- CVE-2004-0118The component for the Virtual DOS Machine (VDM) subsystem in…
- CVE-2004-0119The Negotiate Security Software Provider (SSP) interface in …7.5
- CVE-2004-0120The Microsoft Secure Sockets Layer (SSL) library, as used in…
- CVE-2004-0122Microsoft MSN Messenger 6.0 and 6.1 does not properly handle…
- CVE-2004-0123Double free vulnerability in the ASN.1 library as used in Wi…
- CVE-2004-0124The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, X…
- CVE-2004-0125The jail system call in FreeBSD 4.x before 4.10-RELEASE does…
- CVE-2004-0126The jail_attach system call in FreeBSD 5.1 and 5.2 changes t…
- CVE-2004-0127Directory traversal vulnerability in editconfig_gedcom.php f…
Are you affected by CVE-2004-0121?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
