CVE-2002-0481

Outlook 2002 - Remote Code Execution via HTML Email IFRAME and WMP Media File Handlers

Title source: llm
STIX 2.1

Description

An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass Outlook security settings and execute Javascript via an IFRAME in an HTML email message that references .WMS (Windows Media Skin) or other WMP media files, whose onload handlers execute the player.LaunchURL() Javascript function.

References (3)

Core 3
Core References
Vendor Advisory mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/263429
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4340
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/8604.php

Scores

EPSS 0.1006
EPSS Percentile 95.2%

Details

Status published
Products (1)
microsoft/outlook 2002
Published Aug 12, 2002
Tracked Since Feb 18, 2026