Lucene search

K
cve[email protected]CVE-2002-0617
HistoryApr 02, 2003 - 5:00 a.m.

CVE-2002-0617

2003-04-0205:00:00
web.nvd.nist.gov
20
cve-2002-0617
macro security model
microsoft excel
windows
remote code execution
hyperlinked excel workbook macro bypass
nvd

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

7.1 High

AI Score

Confidence

High

0.026 Low

EPSS

Percentile

90.4%

The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka “Hyperlinked Excel Workbook Macro Bypass.”

Affected configurations

NVD
Node
microsoftexcelMatch2000
OR
microsoftexcelMatch2000sp2
OR
microsoftexcelMatch2000sr1
OR
microsoftexcelMatch2002
OR
microsoftexcelMatch2002sp1
OR
microsoftofficeMatch2000
OR
microsoftofficeMatchxp

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

7.1 High

AI Score

Confidence

High

0.026 Low

EPSS

Percentile

90.4%

Related for CVE-2002-0617