SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-0618

The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script…

HIGH 7.5EPSS 14.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 14.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script Execution".

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
14.50% probability · 96th percentile
CISA KEV
Not listed
Affected
microsoft/excel · microsoft/office
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.