Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
https://exchange.xforce.ibmcloud.com/vulnerabilities/15429
https://exchange.xforce.ibmcloud.com/vulnerabilities/15414
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-009