CVE-2004-0501

Outlook 2003 - Information Disclosure via VML Entity URL Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-0501. PoCs published by http-equiv.

AI-analyzed exploit summary This is a writeup describing a weakness in Microsoft Outlook 2003 that could allow remote attackers to verify the validity of a recipient's e-mail address. The provided code snippet demonstrates the use of VML (Vector Markup Language) to potentially trigger the issue, but it lacks executable exploit code.

Description

Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail message containing a Vector Markup Language (VML) entity whose src parameter points to the remote site, which could allow remote attackers to know when a message has been read, verify valid e-mail addresses, and possibly leak other information.

Exploits (1)

exploitdb WRITEUP VERIFIED
by http-equiv · htmlremotewindows
https://www.exploit-db.com/exploits/24114

This is a writeup describing a weakness in Microsoft Outlook 2003 that could allow remote attackers to verify the validity of a recipient's e-mail address. The provided code snippet demonstrates the use of VML (Vector Markup Language) to potentially trigger the issue, but it lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: Microsoft Outlook 2003
No auth needed
Prerequisites: Victim must open a specially crafted email in Microsoft Outlook 2003
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108637351805607&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16116
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108430168919965&w=2
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10323
Mailing List mailing-list x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=108644231209698&w=2

Scores

EPSS 0.1874
EPSS Percentile 96.9%

Details

Status published
Products (1)
microsoft/outlook 2003
Published Aug 18, 2004
Tracked Since Feb 18, 2026