CVE-2004-0380

EXPLOITED

Microsoft Outlook Express <6 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2004-0380 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 3 public exploits from researchers including anonymous, Liu Die Yu, Liu Die.

AI-analyzed exploit summary The writeup describes a vulnerability in Microsoft Internet Explorer's ITS Protocol URI handler, which can be exploited to execute hostile content in the Local Zone. It includes examples of exploit strings and references to additional proof-of-concept examples.

Description

The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."

Exploits (3)

exploitdb WRITEUP VERIFIED
by anonymous · textremotewindows
https://www.exploit-db.com/exploits/23695

The writeup describes a vulnerability in Microsoft Internet Explorer's ITS Protocol URI handler, which can be exploited to execute hostile content in the Local Zone. It includes examples of exploit strings and references to additional proof-of-concept examples.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Internet Explorer
No auth needed
Prerequisites: Victim must visit a malicious website or open a malicious HTML email · Presence of a non-existent MHTML file on the victim's system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Liu Die Yu · textremotewindows
https://www.exploit-db.com/exploits/23401

The vulnerability in Microsoft Outlook Express involves improper handling of MHTML file and res URIs, allowing an attacker to execute arbitrary code within the Local Zone. This exploit leverages the component's failure to securely handle non-existent resources referenced in MHTML URIs.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Outlook Express 5.5SP2, 6.0, and 6.0SP1
No auth needed
Prerequisites: Victim must visit a malicious webpage
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Liu Die · textremotewindows
https://www.exploit-db.com/exploits/23400

The provided text describes a vulnerability in Microsoft Outlook Express (CVE-2004-0380) where MHTML file and res URIs are mishandled, potentially leading to arbitrary code execution in the Local Zone. The issue affects Outlook Express 5.5SP2, 6.0, and 6.0SP1, and may also impact earlier versions.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Outlook Express 5.5SP2, 6.0, 6.0SP1
No auth needed
Prerequisites: Victim must visit a malicious webpage or open a malicious MHTML file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (14)

Core 14
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A990
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9105
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/323070
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1010
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15705
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9658
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A882
Exploit, Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/358913
Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/354447
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1028
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/10523

Scores

EPSS 0.7441
EPSS Percentile 98.9%

Details

VulnCheck KEV 2004-02-13
Status published
Products (2)
microsoft/outlook_express 5.5
microsoft/outlook_express 6.0
Published May 04, 2004
Tracked Since Feb 18, 2026