← Vulnerability feed

Vulnerability record · CVE-2004-0380 · published 4 May 2004

CVE-2004-0380: Outlook Express MHTML handler domain bypass leads to code execution

Microsoft · Outlook Express

The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through 6 SP1 fails to enforce domain restrictions, letting remote attackers bypass security zones and execute arbitrary code. It matters because the flaw is reachable from a web page and gives full control of the affected system.

10.0 CVSS 2.0 High EPSS 63% · top 0.8%
10.0CVSS 2.0 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
28References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication, and full impact, plus a very high EPSS percentile and public exploit references.

What it is

The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through 6 SP1 fails to enforce domain restrictions, letting remote attackers bypass security zones and execute arbitrary code. It matters because the flaw is reachable from a web page and gives full control of the affected system.

Impact

An attacker can bypass domain restrictions and execute arbitrary code in the context of the victim, leading to complete compromise of confidentiality, integrity and availability.

Attack surface

Reached over the network via a crafted web page or HTML content that invokes the MHTML/ITS protocol handlers (ms-its, ms-itss, its, mk:@MSITStore) in Internet Explorer; no authentication is required, but the victim must view the malicious content.

Exploitation

Not listed in CISA KEV, but EPSS is 0.6325 (99th percentile) and references include an Exploit-tagged advisory, indicating public exploit material exists.

What to do

  • Apply Microsoft security bulletin MS04-013 (the vendor patch) to affected Outlook Express and Internet Explorer installations.
  • Disable or restrict the MHTML/ITS protocol handlers where they are not required.
  • Enforce strict security zone settings and block untrusted sites from invoking MHTML content.
  • Retire or isolate end-of-life Outlook Express and Internet Explorer versions that cannot be patched.

Detection

  • Monitor for processes spawning from Outlook Express or Internet Explorer after opening MHTML or CHM content.
  • Alert on URLs or email content containing ms-its, ms-itss, its, or mk:@MSITStore handlers.
  • Review proxy and web logs for requests to known exploit hosts or CHM/MHTML payloads.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/10523
http://www.k-otik.net/bugtraq/02.18.InternetExplorer.php
http://www.kb.cert.org/vuls/id/323070 US Government Resource
http://www.securityfocus.com/archive/1/354447 PatchVendor Advisory
http://www.securityfocus.com/archive/1/358913 ExploitPatchVendor Advisory
http://www.securityfocus.com/bid/9105
http://www.securityfocus.com/bid/9658
http://www.us-cert.gov/cas/techalerts/TA04-104A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-013
https://exchange.xforce.ibmcloud.com/vulnerabilities/15705
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1010
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1028
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A882
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A990
http://secunia.com/advisories/10523
http://www.k-otik.net/bugtraq/02.18.InternetExplorer.php
http://www.kb.cert.org/vuls/id/323070 US Government Resource
http://www.securityfocus.com/archive/1/354447 PatchVendor Advisory
http://www.securityfocus.com/archive/1/358913 ExploitPatchVendor Advisory
http://www.securityfocus.com/bid/9105
http://www.securityfocus.com/bid/9658
http://www.us-cert.gov/cas/techalerts/TA04-104A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-013
https://exchange.xforce.ibmcloud.com/vulnerabilities/15705
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1010
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1028
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A882
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A990

Track CVE-2004-0380 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-1999-0967Microsoft internet explorer vulnerabilityBuffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.EPSS 6.9%9.3CVE-2010-3147Microsoft outlook express vulnerabilityUntrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, W…EPSS 19%9.3CVE-2010-0816Microsoft outlook express vulnerabilityInteger overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 a…EPSS 20%9.3CVE-2007-3897Microsoft Outlook Express and Windows Mail NNTP heap buffer overflowOutlook Express 6 and earlier, plus Windows Mail on Vista, contain a heap-based buffer overflow triggered by long responses from an NNTP news server.…EPSS 55%analysed8.8CVE-2007-4040Microsoft outlook cross-site scripting vulnerabilityArgument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduc…EPSS 13%8.8CVE-2003-1378Microsoft outlook permissions and access controls vulnerabilityMicrosoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs vi…EPSS 16%7.5CVE-2005-1213Microsoft Outlook Express news reader stack buffer overflow via NNTP LIST responseThe news reader component of Microsoft Outlook Express (MSOE.DLL) contains a stack-based buffer overflow triggered by a long second field in an NNTP …EPSS 74%analysed7.5CVE-2002-1179Microsoft outlook express vulnerabilityBuffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a dig…EPSS 22%

Source: NIST National Vulnerability Database (record CVE-2004-0380), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.