Vulnerability Description
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Excel | 2002 |
| Microsoft | Word | All versions |
References
- http://marc.info/?l=bugtraq&m=103040003014999&w=2Mailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=103252858816401&w=2Mailing ListThird Party Advisory
- http://www.iss.net/security_center/static/10008.phpBroken Link
- http://www.iss.net/security_center/static/10155.phpBroken Link
- http://www.kb.cert.org/vuls/id/899713Third Party AdvisoryUS Government Resource
- http://www.microsoft.com/technet/treeview/default.asp?url=/Technet/security/topiPatchVendor Advisory
- http://www.securityfocus.com/bid/5586ExploitPatchThird Party Advisory
- http://www.securityfocus.com/bid/5764Third Party AdvisoryVDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-05
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Third Party Advisory
- http://marc.info/?l=bugtraq&m=103040003014999&w=2Mailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=103252858816401&w=2Mailing ListThird Party Advisory
- http://www.iss.net/security_center/static/10008.phpBroken Link
- http://www.iss.net/security_center/static/10155.phpBroken Link
- http://www.kb.cert.org/vuls/id/899713Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2002-1143?
CVE-2002-1143 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Wor...
How severe is CVE-2002-1143?
CVE-2002-1143 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1143?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Excel, Microsoft Word.