PT-2002-2438 · Microsoft · Office Xp

Published

2002-12-31

·

Updated

2023-03-07

·

CVE-2002-1716

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Office XP
Description The issue concerns the Host() function in the Microsoft spreadsheet component, which allows remote attackers to create arbitrary files using the SaveAs capability.
Recommendations For Microsoft Office XP, consider disabling the Host() function as a temporary workaround until a patch is available. Restrict access to the SaveAs capability to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CVE-2002-1716

Affected Products

Office Xp