Vulnerability record · CVE-2004-0121 · published 15 April 2004
CVE-2004-0121: Microsoft Outlook 2002 mailto: URL argument injection
Microsoft · Office
Microsoft Outlook 2002 fails to sufficiently filter parameters in mailto: URLs that are passed as arguments when OUTLOOK.EXE is invoked. A crafted mailto: URL can inject arguments that cause script code to run in the Local Machine zone, which is a more trusted context than normal mail content. This matters because it turns a simple link into a path for arbitrary code execution on the victim's machine.
Description
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated argument injection leading to arbitrary code execution, with public exploit references and a high EPSS score, though the affected product is an old Outlook 2002 release.
What it is
Microsoft Outlook 2002 fails to sufficiently filter parameters in mailto: URLs that are passed as arguments when OUTLOOK.EXE is invoked. A crafted mailto: URL can inject arguments that cause script code to run in the Local Machine zone, which is a more trusted context than normal mail content. This matters because it turns a simple link into a path for arbitrary code execution on the victim's machine.
Impact
An attacker can execute arbitrary programs and run script code in the Local Machine zone, effectively gaining the ability to run code with the victim's privileges. This can lead to full compromise of the user's system and data.
Attack surface
Reached remotely via a crafted mailto: URL, typically delivered through a web page, email or other link that invokes OUTLOOK.EXE. No authentication is required per the CVSS vector (AV:N/AC:L/Au:N), though the victim must trigger the URL, so some user interaction is implied by the mailto: handling.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.477 (98.8th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware usage is documented.
What to do
- Apply the Microsoft security update for MS04-009 (Outlook 2002) as the primary fix.
- Apply the mitigations in CERT/CC VU#305206 and the US-CERT TA04-070A alert where patching is not immediately possible.
- Restrict or block mailto: URL handlers and untrusted links that launch OUTLOOK.EXE with attacker-controlled arguments.
- Reduce user exposure by preventing untrusted web and email content from invoking Outlook automatically.
Detection
- Monitor process creation for OUTLOOK.EXE launched with unusual or unexpected command-line arguments, especially from browser or mail clients.
- Alert on mailto: URLs containing suspicious parameter strings or script-like content in email and web gateway logs.
- Review endpoint logs for child processes spawned by OUTLOOK.EXE that are not normal Outlook behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0121 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0121), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.