HIGH · 7.5

CVE-2002-0727

The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via...

Vulnerability Description

The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
MicrosoftOffice Web Components2000
MicrosoftProject2002

References

FAQ

What is CVE-2002-0727?

CVE-2002-0727 is a vulnerability with a CVSS score of 7.5 (HIGH). The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via...

How severe is CVE-2002-0727?

CVE-2002-0727 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-0727?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Office Web Components, Microsoft Project.