PT-2002-2438 · Microsoft · Office Xp
Published
2002-12-31
·
Updated
2023-03-07
·
CVE-2002-1716
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Office XP
Description
The issue concerns the Host() function in the Microsoft spreadsheet component, which allows remote attackers to create arbitrary files using the SaveAs capability.
Recommendations
For Microsoft Office XP, consider disabling the Host() function as a temporary workaround until a patch is available. Restrict access to the SaveAs capability to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Office Xp