Lucene search

K
cve[email protected]CVE-2002-1056
HistoryJun 25, 2002 - 4:00 a.m.

CVE-2002-1056

2002-06-2504:00:00
web.nvd.nist.gov
30
cve-2002-1056
microsoft outlook
email security
remote code execution
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.152 Low

EPSS

Percentile

95.9%

Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.

Affected configurations

NVD
Node
microsoftoutlookMatch2000
OR
microsoftoutlookMatch2002
OR
microsoftwordMatch2000
OR
microsoftwordMatch2000sr1
OR
microsoftwordMatch2000sr1a
OR
microsoftwordMatch2002

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.152 Low

EPSS

Percentile

95.9%

Related for CVE-2002-1056