Vulnerabilities > CVE-2002-1056 - Unspecified vulnerability in Microsoft Outlook and Word
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS02-021.NASL |
description | Outlook 2000 and 2002 provide the option to use Microsoft Word as the email editor when creating and editing email in RTF or HTML. There is a flaw in some versions of Word that could allow an attacker to execute arbitrary code when the user replies to a specially formed message using Word. An attacker could use this flaw to execute arbitrary code on this host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11325 |
published | 2003-03-06 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11325 |
title | MS02-021: Word Mail Reply Arbitrary Script Execution (321804) |
code |
|
Oval
accepted 2012-05-28T04:01:27.874-04:00 class vulnerability contributors name Ingrid Skoog organization The MITRE Corporation name Ingrid Skoog organization The MITRE Corporation name John Hoyland organization Centennial Software name Shane Shaffer organization G2, Inc.
description Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to. family windows id oval:org.mitre.oval:def:205 status accepted submitted 2004-09-06T12:00:00.000-04:00 title MS Outlook (Word 2000) RTF/HTML Script Execution Vulnerability version 6 accepted 2012-05-28T04:01:43.568-04:00 class vulnerability contributors name Ingrid Skoog organization The MITRE Corporation name Jonathan Baker organization The MITRE Corporation name John Hoyland organization Centennial Software name Matthew Wojcik organization The MITRE Corporation name Shane Shaffer organization G2, Inc. name Shane Shaffer organization G2, Inc.
description Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to. family windows id oval:org.mitre.oval:def:429 status accepted submitted 2004-08-24T12:00:00.000-04:00 title MS Outlook (Word 2002) RTF/HTML Script Execution Vulnerability version 8
References
- http://marc.info/?l=bugtraq&m=101760380418890&w=2
- http://online.securityfocus.com/archive/1/265621
- http://www.iss.net/security_center/static/8708.php
- http://www.securityfocus.com/bid/4397
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-021
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A205
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A429