CVE-2002-1143
Summary
| CVE | CVE-2002-1143 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-04-11 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure." |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Excel | 2002 | All | All | All |
| Application | Microsoft | Excel | 2002 | sp1 | All | All |
| Application | Microsoft | Excel | 2002 | sp2 | All | All |
| Application | Microsoft | Word | All | All | All | All |
| Application | Microsoft | Word | 2000 | All | All | All |
| Application | Microsoft | Word | 2000 | sp2 | All | All |
| Application | Microsoft | Word | 2000 | sr1 | All | All |
| Application | Microsoft | Word | 2000 | sr1a | All | All |
| Application | Microsoft | Word | 2001 | All | All | All |
| Application | Microsoft | Word | 2002 | All | All | All |
| Application | Microsoft | Word | 2002 | sp1 | All | All |
| Application | Microsoft | Word | 2002 | sp2 | All | All |
| Application | Microsoft | Word | 97 | All | All | All |
| Application | Microsoft | Word | 97 | sr1 | All | All |
| Application | Microsoft | Word | 97 | sr2 | All | All |
| Application | Microsoft | Word | 98 | All | All | All |
| Application | Microsoft | Word | 98 | All | All | All |
| Application | Microsoft | Word | 98 | All | All | ja |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ISS X-Force Database: word-includepicture-read-files (10155): Microsoft Word INCLUDEPICTURE field in shared documents can be used to read other files | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Broken Link |
| Microsoft Security Bulletin MS02-059 - Moderate | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| 'More vulnerabilities (Re: Security side-effects of Word fields)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List, Third Party Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Third Party Advisory |
| ISS X-Force Database: word-includetext-read-files (10008): Microsoft Word INCLUDETEXT field in shared documents can be used to read other files | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Broken Link |
| Developer tools, technical documentation and coding examples | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | www.microsoft.com | Patch, Vendor Advisory |
| Microsoft Word INCLUDEPICTURE Document Sharing File Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Microsoft Word / Excel INCLUDETEXT Document Sharing File Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory |
| 'Security side-effects of Word fields' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List, Third Party Advisory |
| CERT/CC Vulnerability Note VU#899713 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.