Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/5586 | Exploit Patch Third Party Advisory VDB Entry Vendor Advisory |
http://www.iss.net/security_center/static/10008.php | Broken Link |
http://www.microsoft.com/technet/treeview/default.asp?url=/Technet/security/topics/secword.asp | Patch Vendor Advisory |
http://www.securityfocus.com/bid/5764 | Third Party Advisory VDB Entry |
http://www.iss.net/security_center/static/10155.php | Broken Link |
http://www.kb.cert.org/vuls/id/899713 | Third Party Advisory US Government Resource |
http://marc.info/?l=bugtraq&m=103252858816401&w=2 | Mailing List Third Party Advisory |
http://marc.info/?l=bugtraq&m=103040003014999&w=2 | Mailing List Third Party Advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A202 | Third Party Advisory |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-059 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2003-04-10 21:00
Updated : 2018-10-12 14:32
NVD link : CVE-2002-1143
Mitre link : CVE-2002-1143
JSON object : View
CWE
Products Affected
microsoft
- excel
- word