CVE-2004-0502

Outlook 2003 - Remote Code Execution via Predictable File Location in Email Reply

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-0502. PoCs published by http-equiv.

AI-analyzed exploit summary The code describes a vulnerability in Microsoft Outlook 2003 where files specified in img tags are stored in predictable locations, potentially enabling exploitation of browser-based vulnerabilities. It includes an example img tag demonstrating the issue.

Description

Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as demonstrated using a shell: URI.

Exploits (1)

exploitdb WRITEUP VERIFIED
by http-equiv · textremotewindows
https://www.exploit-db.com/exploits/24101

The code describes a vulnerability in Microsoft Outlook 2003 where files specified in img tags are stored in predictable locations, potentially enabling exploitation of browser-based vulnerabilities. It includes an example img tag demonstrating the issue.

Classification
Writeup 80%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Microsoft Outlook 2003
No auth needed
Prerequisites: Victim must open a malicious email in Microsoft Outlook 2003
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11572
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108637351805607&w=2
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108420583612655&w=2
Mailing List mailing-list x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=108644231209698&w=2
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10307
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16104

Scores

EPSS 0.2017
EPSS Percentile 97.1%

Details

Status published
Products (1)
microsoft/outlook 2003
Published Aug 18, 2004
Tracked Since Feb 18, 2026