PT-2002-1749 · Microsoft · Office Web Components
Published
2002-09-24
·
Updated
2018-10-12
·
CVE-2002-0727
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Office Web Components (OWC) versions 2000 through 2002
Description
The issue concerns the Host function in Microsoft Office Web Components, which is exposed in components marked as safe for scripting. This exposure allows remote attackers to execute arbitrary commands via the setTimeout method.
Recommendations
For Microsoft Office Web Components (OWC) versions 2000 through 2002, consider disabling the Host function in components marked as safe for scripting as a temporary workaround until a patch is available. Restrict access to the setTimeout method to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Office Web Components