CVE-2004-0121: High severity Microsoft Office vulnerability
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0121?
CVE-2004-0121 is considered a critical vulnerability that can lead to remote code execution.
How do I fix CVE-2004-0121?
To fix CVE-2004-0121, apply the security updates provided by Microsoft for Outlook 2002 and Office XP.
Who is affected by CVE-2004-0121?
CVE-2004-0121 affects users of Microsoft Outlook 2002 and Microsoft Office XP, particularly the versions specified.
What types of attacks can result from CVE-2004-0121?
CVE-2004-0121 allows attackers to execute arbitrary programs by injecting script code through mailto: URLs.
Is there a workaround for CVE-2004-0121?
A temporary workaround for CVE-2004-0121 is to avoid using mailto: links with untrusted sources.