First published: Thu Apr 03 2003(Updated: )
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Excel | =2002-sp1 | |
Microsoft Word | =97-sr2 | |
Microsoft Word | =2002-sp1 | |
Microsoft Word | =2000 | |
Microsoft Word | =2000-sr1a | |
Microsoft Word | =97-sr1 | |
Microsoft Word | =98 | |
Microsoft Word | =97 | |
Microsoft Excel | =2002 | |
Microsoft Word | =2002 | |
Microsoft Word | =2000-sp2 | |
Microsoft Word | =2002-sp2 | |
Microsoft Word | =2000-sr1 | |
Microsoft Excel | =2002-sp2 | |
Microsoft Word | =98 | |
Microsoft Word | =98 | |
Microsoft Word | =2001 | |
Microsoft Word |
http://www.microsoft.com/technet/treeview/default.asp?url=/Technet/security/topics/secword.asp
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.