PT-2002-2268 · Microsoft · Office Web Components

Published

2002-12-11

·

Updated

2016-10-18

·

CVE-2002-1339

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Office Web Components (OWC) 10
Description: The issue concerns the "XMLURL" property in the Spreadsheet component, which follows redirections. This allows remote attackers to determine if local files exist based on exceptions or to read WorkSheet XML files.
Recommendations: For Office Web Components (OWC) 10, consider restricting access to the Spreadsheet component until a fix is available. As a temporary workaround, avoid using the "XMLURL" property in sensitive operations to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1339

Affected Products

Office Web Components