8.8

CVE-2003-1378

Exploit

Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftOutlook Version2000
MicrosoftOutlook Version2000 Updatesp2
MicrosoftOutlook Version2000 Updatesr1
MicrosoftOutlook Express Version6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 38.01% 0.971
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 8.6 9.2
AV:N/AC:M/Au:N/C:C/I:C/A:N