CVE-2004-0380
Microsoft Outlook Express <6 - Auth Bypass
Title source: llmDescription
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."
Exploits (3)
exploitdb
WRITEUP
VERIFIED
by anonymous · textremotewindows
https://www.exploit-db.com/exploits/23695
exploitdb
WRITEUP
VERIFIED
by Liu Die Yu · textremotewindows
https://www.exploit-db.com/exploits/23401
References (14)
Scores
EPSS
0.7441
EPSS Percentile
98.9%
Details
Status
published
Products (2)
microsoft/outlook_express
5.5
microsoft/outlook_express
6.0
Published
May 04, 2004
Tracked Since
Feb 18, 2026