CVE-2002-1056
Microsoft Outlook 2000 and 2002 - Arbitrary Script Execution via HTML or RTF Email Forward/Reply
Title source: llmDescription
Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.
References (7)
Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A429
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/4397
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-021
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=101760380418890&w=2
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://online.securityfocus.com/archive/1/265621
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A205
Third Party Advisory vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/8708.php
Scores
EPSS
0.1854
EPSS Percentile
97.0%
Details
Status
published
Products (4)
microsoft/outlook
2000
microsoft/outlook
2002
microsoft/word
2000 (3 CPE variants)
microsoft/word
2002
Published
May 16, 2002
Tracked Since
Feb 18, 2026