PT-2002-2062 · Microsoft · Outlook+1
Published
2002-05-16
·
Updated
2018-10-12
·
CVE-2002-1056
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Microsoft Outlook versions 2000 and 2002
Description:
The issue allows remote attackers to execute arbitrary scripts via an email that the user forwards or replies to, when Microsoft Outlook is configured to use Microsoft Word as the email editor and the email message is in HTML or Rich Text Format (RTF).
Recommendations:
For Microsoft Outlook 2000, consider disabling the use of Microsoft Word as the email editor until a fix is available.
For Microsoft Outlook 2002, consider disabling the use of Microsoft Word as the email editor until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Outlook
Office Word