CVE-2002-1143: Medium severity microsoft excel vulnerability
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1143?
CVE-2002-1143 has a medium severity rating due to the potential for sensitive information disclosure.
How do I fix CVE-2002-1143?
To fix CVE-2002-1143, users should apply the latest security patches released by Microsoft for affected versions of Word and Excel.
What software is affected by CVE-2002-1143?
CVE-2002-1143 affects various versions of Microsoft Word and Microsoft Excel, including versions 97, 2000, and 2002.
What exploit methods are utilized in CVE-2002-1143?
CVE-2002-1143 exploits certain field codes in Word and Excel, such as INCLUDETEXT and INCLUDEPICTURE, to steal sensitive information.
Is CVE-2002-1143 still a threat today?
While CVE-2002-1143 is not commonly exploited today, it is advisable to update to supported software versions to mitigate any potential risks.