PT-2002-2269 · Microsoft · Office Web Components

Published

2002-12-11

·

Updated

2016-10-18

·

CVE-2002-1340

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Office Web Components (OWC) version 10
Description: The issue allows remote attackers to determine the existence of local files by detecting an exception related to the "ConnectionFile" property in the DataSourceControl component.
Recommendations: For Office Web Components (OWC) version 10, consider restricting access to the DataSourceControl component to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1340

Affected Products

Office Web Components