PT-2002-1749 · Microsoft · Office Web Components

Publicado

2002-09-24

·

Atualizado

2018-10-12

·

CVE-2002-0727

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Office Web Components (OWC) versions 2000 through 2002
Description The issue concerns the Host function in Microsoft Office Web Components, which is exposed in components marked as safe for scripting. This exposure allows remote attackers to execute arbitrary commands via the setTimeout method.
Recommendations For Microsoft Office Web Components (OWC) versions 2000 through 2002, consider disabling the Host function in components marked as safe for scripting as a temporary workaround until a patch is available. Restrict access to the setTimeout method to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0727

Produtos afetados

Office Web Components