PT-2002-1749 · Microsoft · Office Web Components

Published

2002-09-24

·

Updated

2018-10-12

·

CVE-2002-0727

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Office Web Components (OWC) versions 2000 through 2002
Description The issue concerns the Host function in Microsoft Office Web Components, which is exposed in components marked as safe for scripting. This exposure allows remote attackers to execute arbitrary commands via the setTimeout method.
Recommendations For Microsoft Office Web Components (OWC) versions 2000 through 2002, consider disabling the Host function in components marked as safe for scripting as a temporary workaround until a patch is available. Restrict access to the setTimeout method to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0727

Affected Products

Office Web Components