VulnerabilityModified
CVE-2002-1716
The Host() function in the Microsoft spreadsheet component on Microsoft Office XP allows remote attackers to create arbitrary files using the SaveAs capability.
MEDIUM 5.0EPSS 14.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.3%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The Host() function in the Microsoft spreadsheet component on Microsoft Office XP allows remote attackers to create arbitrary files using the SaveAs capability.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 14.26% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/office
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/archive/1/265087Broken Link, Third Party Advisory, VDB Entry
- http://www.guninski.com/m%24oxp-2.html
- http://www.securityfocus.com/bid/4398Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8711Third Party Advisory, VDB Entry
- http://online.securityfocus.com/archive/1/265087Broken Link, Third Party Advisory, VDB Entry
- http://www.guninski.com/m%24oxp-2.html
- http://www.securityfocus.com/bid/4398Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8711Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.