CVE-2002-1056: High severity Microsoft Outlook vulnerability

Published May 16, 2002
·
Updated

Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.

Affected Software

6 affected components
Microsoft Outlook=2000
Microsoft Word=2000
Microsoft Word=2000-sr1a
Microsoft Word=2002
Microsoft Outlook=2002
Microsoft Word=2000-sr1

Event History

May 16, 2002
CVE Published
04:00 AM
Jun 25, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2002-1056?

CVE-2002-1056 is considered a moderate severity vulnerability due to its potential to allow arbitrary script execution.

2

How do I fix CVE-2002-1056?

To mitigate CVE-2002-1056, you should disable the use of Microsoft Word as the email editor in Outlook or apply any available patches from Microsoft.

3

Which versions of Microsoft Outlook are affected by CVE-2002-1056?

CVE-2002-1056 affects Microsoft Outlook 2000 and 2002 when configured to use Word as the email editor.

4

What impact does CVE-2002-1056 have on users?

CVE-2002-1056 allows attackers to execute arbitrary scripts on the user's machine through crafted email messages.

5

Is CVE-2002-1056 related to any versions of Microsoft Word?

Yes, CVE-2002-1056 also affects Microsoft Word 2000 and 2002 when used as the email editor in Outlook.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203