CVE-2004-0503

Microsoft Outlook 2003 - Auth Bypass

Title source: llm
STIX 2.1

Description

Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's setting to disallow scripting and may lead to unprompted installation of an executable when exploited in conjunction with predictable-file-location exposures such as CVE-2004-0502.

References (6)

Core 6
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108483193328605&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/6217
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0885.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16173
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11629
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10369

Scores

EPSS 0.1144
EPSS Percentile 95.6%

Details

Status published
Products (1)
microsoft/outlook 2003
Published Aug 18, 2004
Tracked Since Feb 18, 2026