PT-2002-2268 · Microsoft · Office Web Components
Published
2002-12-11
·
Updated
2016-10-18
·
CVE-2002-1339
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Office Web Components (OWC) 10
Description:
The issue concerns the "XMLURL" property in the Spreadsheet component, which follows redirections. This allows remote attackers to determine if local files exist based on exceptions or to read WorkSheet XML files.
Recommendations:
For Office Web Components (OWC) 10, consider restricting access to the Spreadsheet component until a fix is available. As a temporary workaround, avoid using the "XMLURL" property in sensitive operations to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Office Web Components