← Vulnerability feed

Vulnerability record · CVE-2004-0121 · published 15 April 2004

CVE-2004-0121: Microsoft Outlook 2002 mailto: URL argument injection

Microsoft · Office

Microsoft Outlook 2002 fails to sufficiently filter parameters in mailto: URLs that are passed as arguments when OUTLOOK.EXE is invoked. A crafted mailto: URL can inject arguments that cause script code to run in the Local Machine zone, which is a more trusted context than normal mail content. This matters because it turns a simple link into a path for arbitrary code execution on the victim's machine.

7.5 CVSS 2.0 High EPSS 48% · top 1.2% CWE-88 · Argument injection
7.5CVSS 2.0 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
20References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote, unauthenticated argument injection leading to arbitrary code execution, with public exploit references and a high EPSS score, though the affected product is an old Outlook 2002 release.

What it is

Microsoft Outlook 2002 fails to sufficiently filter parameters in mailto: URLs that are passed as arguments when OUTLOOK.EXE is invoked. A crafted mailto: URL can inject arguments that cause script code to run in the Local Machine zone, which is a more trusted context than normal mail content. This matters because it turns a simple link into a path for arbitrary code execution on the victim's machine.

Impact

An attacker can execute arbitrary programs and run script code in the Local Machine zone, effectively gaining the ability to run code with the victim's privileges. This can lead to full compromise of the user's system and data.

Attack surface

Reached remotely via a crafted mailto: URL, typically delivered through a web page, email or other link that invokes OUTLOOK.EXE. No authentication is required per the CVSS vector (AV:N/AC:L/Au:N), though the victim must trigger the URL, so some user interaction is implied by the mailto: handling.

Exploitation

Not listed in CISA KEV, but EPSS is high at roughly 0.477 (98.8th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware usage is documented.

What to do

  • Apply the Microsoft security update for MS04-009 (Outlook 2002) as the primary fix.
  • Apply the mitigations in CERT/CC VU#305206 and the US-CERT TA04-070A alert where patching is not immediately possible.
  • Restrict or block mailto: URL handlers and untrusted links that launch OUTLOOK.EXE with attacker-controlled arguments.
  • Reduce user exposure by preventing untrusted web and email content from invoking Outlook automatically.

Detection

  • Monitor process creation for OUTLOOK.EXE launched with unusual or unexpected command-line arguments, especially from browser or mail clients.
  • Alert on mailto: URLs containing suspicious parameter strings or script-like content in email and web gateway logs.
  • Review endpoint logs for child processes spawned by OUTLOOK.EXE that are not normal Outlook behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://marc.info/?l=bugtraq&m=107893704602842&w=2 Third Party Advisory
http://www.ciac.org/ciac/bulletins/o-096.shtml Broken Link
http://www.idefense.com/application/poi/display?id=79&type=vulnerabilities Broken LinkPatchVendor Advisory
http://www.kb.cert.org/vuls/id/305206 MitigationThird Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/9827 Broken LinkExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
http://www.us-cert.gov/cas/techalerts/TA04-070A.html Broken LinkThird Party AdvisoryUS Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-009 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/15414 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15429 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A843 Broken Link
http://marc.info/?l=bugtraq&m=107893704602842&w=2 Third Party Advisory
http://www.ciac.org/ciac/bulletins/o-096.shtml Broken Link
http://www.idefense.com/application/poi/display?id=79&type=vulnerabilities Broken LinkPatchVendor Advisory
http://www.kb.cert.org/vuls/id/305206 MitigationThird Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/9827 Broken LinkExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
http://www.us-cert.gov/cas/techalerts/TA04-070A.html Broken LinkThird Party AdvisoryUS Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-009 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/15414 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15429 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A843 Broken Link

Track CVE-2004-0121 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2015-1770Microsoft Office uninitialized memory use allows remote code executionMicrosoft Office 2013 SP1 and 2013 RT SP1 mishandle uninitialized memory when parsing a crafted Office document, which can lead to arbitrary code exe…KEVEPSS 35%analysed8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed

Source: NIST National Vulnerability Database (record CVE-2004-0121), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.