CVE-2002-0618
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script Execution".
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 14.50% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/excel · microsoft/office
- Source
- cve@mitre.org
References
- http://marc.info/?l=ntbugtraq&m=102256054320377&w=2
- http://www.guninski.com/ex%24el2.html
- http://www.iss.net/security_center/static/9399.php
- http://www.securityfocus.com/bid/4821
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-031
- http://marc.info/?l=ntbugtraq&m=102256054320377&w=2
- http://www.guninski.com/ex%24el2.html
- http://www.iss.net/security_center/static/9399.php
- http://www.securityfocus.com/bid/4821
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-031
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.