CVE-2002-0727

Microsoft Office Web Components <2003 - RCE

Title source: llm
STIX 2.1

Description

The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/3006
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/8777.php
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=101829645415486&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4449

Scores

EPSS 0.1885
EPSS Percentile 97.0%

Details

Status published
Products (3)
microsoft/office_web_components 2000
microsoft/office_web_components 2002
microsoft/project 2002
Published Sep 24, 2002
Tracked Since Feb 18, 2026