CVE-2002-1143 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 53.6% (pctl 99)
Patch early
A public exploit exists.
Description
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 53.56% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-04-11 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | excel |
| microsoft | word |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Word 95/97/98/2000/2002 - 'INCLUDEPICTURE' Document Sharing File Disclosure | 2002-09-20 |
| exploit-db | Microsoft Word 95/97/98/2000/2002 / Excel 2002 - INCLUDETEXT Document Sharing File Disclosure | 2002-08-26 |
References
- http://marc.info/?l=bugtraq&m=103040003014999&w=2
- http://marc.info/?l=bugtraq&m=103252858816401&w=2
- http://www.iss.net/security_center/static/10008.php
- http://www.iss.net/security_center/static/10155.php
- http://www.kb.cert.org/vuls/id/899713
- http://www.microsoft.com/technet/treeview/default.asp?url=/Technet/security/topics/secword.asp
- http://www.securityfocus.com/bid/5586
- http://www.securityfocus.com/bid/5764
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-059
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A202
- http://marc.info/?l=bugtraq&m=103040003014999&w=2
- http://marc.info/?l=bugtraq&m=103252858816401&w=2
- http://www.iss.net/security_center/static/10008.php
- http://www.iss.net/security_center/static/10155.php
- http://www.kb.cert.org/vuls/id/899713
- http://www.microsoft.com/technet/treeview/default.asp?url=/Technet/security/topics/secword.asp
- http://www.securityfocus.com/bid/5586
- http://www.securityfocus.com/bid/5764
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-059
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A202
→ the Explorer · watch your stack · NVD