The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."
Published Apr 6, 2004
10.0
HIGHCVSS 2.0
EPSS 63.25%
Description
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."
Affected products
No data.
- 5.5
- 6.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 63.25% (0.63250) | 99.18th | v5 (v2026.06.15) |
| Jun 15, 2026 | 63.25% (0.63250) | 99.10th | v5 (v2026.06.15) |
| Mar 16, 2026 | 74.41% (0.74413) | 98.83th | v4 (v2025.03.14) |
| Jul 13, 2025 | 81.69% (0.81694) | 99.13th | v4 (v2025.03.14) |
| Mar 29, 2025 | 80.35% (0.80352) | 98.87th | v4 (v2025.03.14) |
| Mar 17, 2025 | 78.46% (0.78461) | 98.98th | v4 (v2025.03.14) |
| Dec 12, 2024 | 96.71% (0.96707) | 99.71th | v3 (v2023.03.01) |
| Apr 21, 2024 | 96.76% (0.96759) | 99.66th | v3 (v2023.03.01) |
| Oct 13, 2023 | 96.59% (0.96593) | 99.48th | v3 (v2023.03.01) |
| Mar 14, 2023 | 96.63% (0.96625) | 99.33th | v3 (v2023.03.01) |
| Mar 7, 2023 | 96.45% (0.96452) | 99.24th | v3 (v2023.03.01) |
| Mar 6, 2023 | 63.98% (0.63976) | 99.01th | v2 (v2022.01.01) |
| Feb 4, 2022 | 63.98% (0.63976) | 98.77th | v2 (v2022.01.01) |
No CWE recorded.
References (14)
- http://secunia.com/advisories/10523 third-party-advisoryx_refsource_SECUNIA
- http://www.k-otik.net/bugtraq/02.18.InternetExplorer.php x_refsource_MISC
- http://www.kb.cert.org/vuls/id/323070 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.securityfocus.com/archive/1/354447 mailing-listx_refsource_BUGTRAQPatchVendor Advisory
- http://www.securityfocus.com/archive/1/358913 mailing-listx_refsource_BUGTRAQExploitPatchVendor Advisory
- http://www.securityfocus.com/bid/9105 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/9658 vdb-entryx_refsource_BID
- http://www.us-cert.gov/cas/techalerts/TA04-104A.html third-party-advisoryx_refsource_CERTUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-013 vendor-advisoryx_refsource_MS
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15705 vdb-entryx_refsource_XF
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1010 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1028 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A882 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A990 vdb-entrysignaturex_refsource_OVAL
Change history (0)
No recorded changes yet.