← Back to browse · API

CVE-2007-4040

Severity
HIGH
CVSS
8.8
EPSS
0.13472
Risk score
39.92
CISA KEV
No
PoC
No
Published
2007-07-27
Modified
2025-04-03
First seen
2026-08-07
Aliases
EUVD-2007-4024, GHSA-2MGM-7FRW-WMJM
Products
n/a:n/a n/a
Sources
euvd EUVD-2007-4024

Description

Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.

References