CVE-2002-1056

Microsoft Outlook 2000 and 2002 - Arbitrary Script Execution via HTML or RTF Email Forward/Reply

Title source: llm
STIX 2.1

Description

Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A429
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4397
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=101760380418890&w=2
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/265621
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A205
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/8708.php

Scores

EPSS 0.1854
EPSS Percentile 97.0%

Details

Status published
Products (4)
microsoft/outlook 2000
microsoft/outlook 2002
microsoft/word 2000 (3 CPE variants)
microsoft/word 2002
Published May 16, 2002
Tracked Since Feb 18, 2026