CVE-2002-0617
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka "Hyperlinked Excel Workbook Macro Bypass."
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 10.78% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/excel · microsoft/office
- Source
- cve@mitre.org
References
- http://www.osvdb.org/5175
- http://www.securityfocus.com/bid/5064
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-031
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9398
- http://www.osvdb.org/5175
- http://www.securityfocus.com/bid/5064
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-031
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9398
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.