Security Advisory

CVE-2002-1143

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2003-04-03 05:00:00
Last updated 2024-08-08 03:12:17
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."