← All CVEs

CVE-2002-1143

medium · 5

Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."

5
CVSS
53.6%
EPSS (exploit prob.)
99th
EPSS percentile
2003-04-11
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

VendorProductAffected versions
microsoftexcel2002
microsoftexcel2002
microsoftexcel2002
microsoftwordall versions
microsoftword97
microsoftword97
microsoftword97
microsoftword98
microsoftword98
microsoftword98
microsoftword2000
microsoftword2000
microsoftword2000
microsoftword2000
microsoftword2001
microsoftword2002
microsoftword2002
microsoftword2002

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-1143