First published: Wed Dec 11 2002(Updated: )
The Load method in the Chart component of Office Web Components (OWC) 9 and 10 generates an exception when a specified file does not exist, which allows remote attackers to determine the existence of local files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Web Components | =2002 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1338 is considered a moderate severity vulnerability due to its potential for unauthorized file existence disclosure.
To fix CVE-2002-1338, you should update to a supported version of Microsoft Office Web Components or implement proper access controls.
CVE-2002-1338 exploits a flaw in the Load method of the Chart component in Office Web Components, allowing attackers to infer the existence of local files.
CVE-2002-1338 affects Microsoft Office Web Components versions 2002 and 2003.
While CVE-2002-1338 primarily discloses file existence, it could lead to further attacks if other vulnerabilities are present that exploit the information gained.