Vulnerability record · CVE-2001-0538 · published 14 August 2001
CVE-2001-0538: Microsoft Outlook View ActiveX Control allows remote command execution
Microsoft · Outlook
The Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier fails to properly restrict how it is invoked, so a malicious HTML e-mail or web page can cause it to execute arbitrary commands. Because the control is reachable from ordinary mail and web content, the flaw turns simply viewing a crafted message or page into a code execution path. The record does not specify the exact coding error beyond a generic 'Other' CWE.
Description
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityThe flaw allows unauthenticated remote code execution from ordinary e-mail or web content with complete impact, and the high EPSS score signals elevated exploitation likelihood despite the absence of KEV listing.
What it is
The Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier fails to properly restrict how it is invoked, so a malicious HTML e-mail or web page can cause it to execute arbitrary commands. Because the control is reachable from ordinary mail and web content, the flaw turns simply viewing a crafted message or page into a code execution path. The record does not specify the exact coding error beyond a generic 'Other' CWE.
Impact
An attacker gains arbitrary command execution in the context of the user who opens the malicious e-mail or visits the malicious page, which can lead to full compromise of the workstation. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.
Attack surface
The vector is network-reachable with no authentication and no user interaction beyond rendering the HTML e-mail or web page in Outlook or a browser hosting the control. No credentials or special privileges are required on the attacker side.
Exploitation
The record is not listed in CISA KEV and no reference carries an exploit tag, but EPSS is 0.52851 (99th percentile), indicating a high modeled likelihood of exploitation activity. No public exploit code or in-the-wild confirmation is stated in the supplied data.
What to do
- Apply Microsoft security bulletin MS01-038, which addresses this Outlook View ActiveX Control issue, or upgrade to a fixed Outlook release.
- Disable or kill-bit the Outlook View ActiveX Control in Internet Explorer and Outlook where it is not required.
- Configure Outlook to read e-mail as plain text and block active content in HTML messages.
- Restrict or disable ActiveX execution in the browser and mail client zones used by end users.
- Treat this as legacy software: retire Outlook 2002 and earlier from production where feasible.
Detection
- Monitor for Outlook or browser processes spawning unexpected child processes such as cmd.exe or script hosts after mail or web rendering.
- Audit registry and policy settings for the Outlook View ActiveX Control kill-bit and ActiveX restrictions on endpoints.
- Review proxy and mail gateway logs for HTML content referencing the Outlook View ActiveX Control or suspicious object embedding.
- Inventory endpoints still running Outlook 2002 or earlier to identify exposed hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2001-0538 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2001-0538), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.