Описание
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Broken Link
- Broken Link
- Third Party AdvisoryUS Government Resource
- PatchVendor Advisory
- ExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Broken Link
- Broken Link
- Third Party AdvisoryUS Government Resource
- PatchVendor Advisory
- ExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2002:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2002:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:word:*:*:*:*:*:mac_os_x:*:*
cpe:2.3:a:microsoft:word:97:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:word:97:sr1:*:*:*:*:*:*
cpe:2.3:a:microsoft:word:97:sr2:*:*:*:*:*:*
cpe:2.3:a:microsoft:word:98:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:word:98:*:*:*:*:mac_os_x:*:*
cpe:2.3:a:microsoft:word:98:*:*:ja:*:*:*:*
cpe:2.3:a:microsoft:word:2000:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:word:2000:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:word:2000:sr1:*:*:*:*:*:*
cpe:2.3:a:microsoft:word:2000:sr1a:*:*:*:*:*:*
cpe:2.3:a:microsoft:word:2001:*:*:*:*:mac_os_x:*:*
cpe:2.3:a:microsoft:word:2002:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:word:2002:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:word:2002:sp2:*:*:*:*:*:*
EPSS
Процентиль: 97%
0.32477
Средний
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."
EPSS
Процентиль: 97%
0.32477
Средний
5 Medium
CVSS2
Дефекты
NVD-CWE-Other