Synced 19 Jun 2026 07:34 UTC Account
← All products

CVE-2003-1378

HIGH severity · CVSS 8.8 · CWE-264
8.8CVSS HIGH

Summary

Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.

Impact & exploitability

Attack vectorNetwork
Attack complexity
Privileges required
User interaction
Confidentiality impact
Integrity impact
Availability impactNone
Exploit probability (EPSS)16%

AV:N/AC:M/Au:N/C:C/I:C/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.