CVE-2002-1338: Medium severity microsoft office web components vulnerability
The Load method in the Chart component of Office Web Components (OWC) 9 and 10 generates an exception when a specified file does not exist, which allows remote attackers to determine the existence of local files.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1338?
CVE-2002-1338 is considered a moderate severity vulnerability due to its potential for unauthorized file existence disclosure.
How do I fix CVE-2002-1338?
To fix CVE-2002-1338, you should update to a supported version of Microsoft Office Web Components or implement proper access controls.
What does CVE-2002-1338 exploit?
CVE-2002-1338 exploits a flaw in the Load method of the Chart component in Office Web Components, allowing attackers to infer the existence of local files.
Which versions are affected by CVE-2002-1338?
CVE-2002-1338 affects Microsoft Office Web Components versions 2002 and 2003.
Can CVE-2002-1338 lead to further attacks?
While CVE-2002-1338 primarily discloses file existence, it could lead to further attacks if other vulnerabilities are present that exploit the information gained.