CVE-2002-1056: High severity Microsoft Outlook vulnerability
Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1056?
CVE-2002-1056 is considered a moderate severity vulnerability due to its potential to allow arbitrary script execution.
How do I fix CVE-2002-1056?
To mitigate CVE-2002-1056, you should disable the use of Microsoft Word as the email editor in Outlook or apply any available patches from Microsoft.
Which versions of Microsoft Outlook are affected by CVE-2002-1056?
CVE-2002-1056 affects Microsoft Outlook 2000 and 2002 when configured to use Word as the email editor.
What impact does CVE-2002-1056 have on users?
CVE-2002-1056 allows attackers to execute arbitrary scripts on the user's machine through crafted email messages.
Is CVE-2002-1056 related to any versions of Microsoft Word?
Yes, CVE-2002-1056 also affects Microsoft Word 2000 and 2002 when used as the email editor in Outlook.