peter bassill · operator
$ cve CVE-2002-1143 JSON

CVE-2002-1143 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 53.6% (pctl 99)

Patch early

A public exploit exists.

Description

Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS53.56% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2003-04-11
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftexcel
microsoftword

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD