First published: Thu Apr 03 2003(Updated: )
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Excel for Mac | =2002-sp1 | |
Microsoft Word for Android | =97-sr2 | |
Microsoft Word for Android | =2002-sp1 | |
Microsoft Word for Android | =2000 | |
Microsoft Word for Android | =2000-sr1a | |
Microsoft Word for Android | =97-sr1 | |
Microsoft Word for Android | =98 | |
Microsoft Word for Android | =97 | |
Microsoft Excel for Mac | =2002 | |
Microsoft Word for Android | =2002 | |
Microsoft Word for Android | =2000-sp2 | |
Microsoft Word for Android | =2002-sp2 | |
Microsoft Word for Android | =2000-sr1 | |
Microsoft Excel for Mac | =2002-sp2 | |
Microsoft Word for Android | =98 | |
Microsoft Word for Mac | =98 | |
Microsoft Word for Mac | =2001 | |
Microsoft Word for Mac |
http://www.microsoft.com/technet/treeview/default.asp?url=/Technet/security/topics/secword.asp
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1143 has a medium severity rating due to the potential for sensitive information disclosure.
To fix CVE-2002-1143, users should apply the latest security patches released by Microsoft for affected versions of Word and Excel.
CVE-2002-1143 affects various versions of Microsoft Word and Microsoft Excel, including versions 97, 2000, and 2002.
CVE-2002-1143 exploits certain field codes in Word and Excel, such as INCLUDETEXT and INCLUDEPICTURE, to steal sensitive information.
While CVE-2002-1143 is not commonly exploited today, it is advisable to update to supported software versions to mitigate any potential risks.