Unrated severityNVD Advisory· Published Apr 15, 2004· Updated Apr 16, 2026
CVE-2004-0121
CVE-2004-0121
Description
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.idefense.com/application/poi/displaynvdBroken LinkPatchVendor Advisory
- docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-009nvdPatchVendor Advisory
- www.securityfocus.com/bid/9827nvdBroken LinkExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
- marc.infonvdThird Party Advisory
- www.kb.cert.org/vuls/id/305206nvdMitigationThird Party AdvisoryUS Government Resource
- www.us-cert.gov/cas/techalerts/TA04-070A.htmlnvdBroken LinkThird Party AdvisoryUS Government Resource
- exchange.xforce.ibmcloud.com/vulnerabilities/15414nvdThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/15429nvdThird Party AdvisoryVDB Entry
- www.ciac.org/ciac/bulletins/o-096.shtmlnvdBroken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A843nvdBroken Link
News mentions
0No linked articles in our index yet.