4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.1 High
AI Score
Confidence
High
0.512 Medium
EPSS
Percentile
97.6%
Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.
CPE | Name | Operator | Version |
---|---|---|---|
microsoft:outlook | microsoft outlook | eq | * |
microsoft:outlook_express | microsoft outlook express | eq | * |