{"api_version":"1","generated_at":"2026-07-23T06:28:25+00:00","cve":"CVE-2002-0618","urls":{"html":"https://cve.report/CVE-2002-0618","api":"https://cve.report/api/cve/CVE-2002-0618.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0618","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0618"},"summary":{"title":"CVE-2002-0618","description":"The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka \"Excel XSL Stylesheet Script Execution\".","state":"PUBLISHED","assigner":"mitre","published_at":"2002-08-12 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-031","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-031","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS02-031 - Moderate | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/9399.php","name":"http://www.iss.net/security_center/static/9399.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database: excel-xsl-script-execution (9399): Microsoft Excel XSL Stylesheet allows attacker to execute script code","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://marc.info/?l=ntbugtraq&m=102256054320377&w=2","name":"http://marc.info/?l=ntbugtraq&m=102256054320377&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Excel XP xml stylesheet problems' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.guninski.com/ex%24el2.html","name":"http://www.guninski.com/ex%24el2.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Excel XP xml stylesheet problems","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/4821","name":"http://www.securityfocus.com/bid/4821","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Excel XML Stylesheet Arbitrary Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.guninski.com/ex$el2.html","name":"MISC:http://www.guninski.com/ex$el2.html","refsource":"MITRE","tags":[],"title":"Excel XP xml stylesheet problems","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0618","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0618","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"618","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"excel","cpe6":"2000","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"618","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"excel","cpe6":"2000","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"618","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"excel","cpe6":"2000","cpe7":"sr1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"618","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"excel","cpe6":"2002","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"618","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"excel","cpe6":"2002","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"618","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"office","cpe6":"2000","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"618","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"office","cpe6":"xp","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:56:38.631Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20020524 Excel XP xml stylesheet problems","tags":["mailing-list","x_refsource_NTBUGTRAQ","x_transferred"],"url":"http://marc.info/?l=ntbugtraq&m=102256054320377&w=2"},{"name":"4821","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4821"},{"name":"MS02-031","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-031"},{"name":"excel-xsl-script-execution(9399)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/9399.php"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.guninski.com/ex%24el2.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-06-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka \"Excel XSL Stylesheet Script Execution\"."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2003-03-21T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20020524 Excel XP xml stylesheet problems","tags":["mailing-list","x_refsource_NTBUGTRAQ"],"url":"http://marc.info/?l=ntbugtraq&m=102256054320377&w=2"},{"name":"4821","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4821"},{"name":"MS02-031","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-031"},{"name":"excel-xsl-script-execution(9399)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/9399.php"},{"tags":["x_refsource_MISC"],"url":"http://www.guninski.com/ex%24el2.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0618","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka \"Excel XSL Stylesheet Script Execution\"."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20020524 Excel XP xml stylesheet problems","refsource":"NTBUGTRAQ","url":"http://marc.info/?l=ntbugtraq&m=102256054320377&w=2"},{"name":"4821","refsource":"BID","url":"http://www.securityfocus.com/bid/4821"},{"name":"MS02-031","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-031"},{"name":"excel-xsl-script-execution(9399)","refsource":"XF","url":"http://www.iss.net/security_center/static/9399.php"},{"name":"http://www.guninski.com/ex$el2.html","refsource":"MISC","url":"http://www.guninski.com/ex$el2.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0618","datePublished":"2003-04-02T05:00:00.000Z","dateReserved":"2002-06-12T00:00:00.000Z","dateUpdated":"2024-08-08T02:56:38.631Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-08-12 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:*","matchCriteriaId":"F55D42D5-7371-47C2-BF55-B7F51C19B61E"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:excel:2000:sp2:*:*:*:*:*:*","matchCriteriaId":"D4FBEB90-1BF2-4E84-9A74-EAD226AAA0A2"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:excel:2000:sr1:*:*:*:*:*:*","matchCriteriaId":"27C6E1BC-406E-4B0B-B513-33226AC4482D"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:*","matchCriteriaId":"082D3262-87E3-4245-AD9C-02BE0871FA3B"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:excel:2002:sp1:*:*:*:*:*:*","matchCriteriaId":"C619E79B-90FB-4812-B0F3-115B47498492"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:office:2000:*:*:*:*:*:*:*","matchCriteriaId":"A9A82D13-513C-46FA-AF51-0582233E230A"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:office:xp:*:*:*:*:*:*:*","matchCriteriaId":"34FA62BE-D804-402D-9BDD-68BC70ECCD76"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"618","Ordinal":"1","Title":"CVE-2002-0618","CVE":"CVE-2002-0618","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"618","Ordinal":"1","NoteData":"The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka \"Excel XSL Stylesheet Script Execution\".","Type":"Description","Title":"CVE-2002-0618"},{"CveYear":"2002","CveId":"618","Ordinal":"2","NoteData":"2003-04-02","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"618","Ordinal":"3","NoteData":"2003-03-20","Type":"Other","Title":"Modified"}]}}}