Vulnerability record · CVE-2004-0380 · published 4 May 2004
CVE-2004-0380: Outlook Express MHTML handler domain bypass leads to code execution
Microsoft · Outlook Express
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through 6 SP1 fails to enforce domain restrictions, letting remote attackers bypass security zones and execute arbitrary code. It matters because the flaw is reachable from a web page and gives full control of the affected system.
Description
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication, and full impact, plus a very high EPSS percentile and public exploit references.
What it is
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through 6 SP1 fails to enforce domain restrictions, letting remote attackers bypass security zones and execute arbitrary code. It matters because the flaw is reachable from a web page and gives full control of the affected system.
Impact
An attacker can bypass domain restrictions and execute arbitrary code in the context of the victim, leading to complete compromise of confidentiality, integrity and availability.
Attack surface
Reached over the network via a crafted web page or HTML content that invokes the MHTML/ITS protocol handlers (ms-its, ms-itss, its, mk:@MSITStore) in Internet Explorer; no authentication is required, but the victim must view the malicious content.
Exploitation
Not listed in CISA KEV, but EPSS is 0.6325 (99th percentile) and references include an Exploit-tagged advisory, indicating public exploit material exists.
What to do
- Apply Microsoft security bulletin MS04-013 (the vendor patch) to affected Outlook Express and Internet Explorer installations.
- Disable or restrict the MHTML/ITS protocol handlers where they are not required.
- Enforce strict security zone settings and block untrusted sites from invoking MHTML content.
- Retire or isolate end-of-life Outlook Express and Internet Explorer versions that cannot be patched.
Detection
- Monitor for processes spawning from Outlook Express or Internet Explorer after opening MHTML or CHM content.
- Alert on URLs or email content containing ms-its, ms-itss, its, or mk:@MSITStore handlers.
- Review proxy and web logs for requests to known exploit hosts or CHM/MHTML payloads.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0380 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0380), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.