PT-2004-3374 · Microsoft · Outlook+1

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2482

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft Outlook versions 2000 through 2003
Description: The issue occurs when Microsoft Outlook is configured to use Microsoft Word as the e-mail editor and the user forwards an e-mail. It fails to properly handle an opening OBJECT tag without a corresponding closing OBJECT tag. This causes Outlook to automatically download the URI specified in the data property of the OBJECT tag, potentially allowing remote attackers to execute arbitrary code.
Recommendations: For Microsoft Outlook versions 2000 through 2003, consider disabling the use of Microsoft Word as the e-mail editor until a fix is available. As a temporary workaround, avoid forwarding e-mails that may contain malicious OBJECT tags.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2482

Affected Products

Outlook
Office Word