« Volver al listado

CVE-2002-0861

Estado: ModificadaAlta (7.5)—

Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2002-0861",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": true,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2002-09-24T04:00:00.000",
  "references": [
    {
      "url": "http://marc.info/?l=bugtraq&m=101829726516346&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.iss.net/security_center/static/8779.php",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/4457",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-044",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=101829726516346&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.iss.net/security_center/static/8779.php",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/4457",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-044",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the \"Allow paste operations via script\" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object."
    },
    {
      "lang": "es",
      "value": "Microsoft Office Web Components (OWC) 2000 y 2002 permite a atacantes remotos sortear la configuración de \"Permitir pegar mediante script\", incluso cuando está desactivada, mediante:\r\nel método Copy del objeto Cell (celda)\r\nel método Paste (pegar) del objeto Range (rango)"
    }
  ],
  "lastModified": "2026-06-16T21:58:17.023",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:office_web_components:2000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A431CA59-8BD3-48CB-82BC-8FDCFE7440FA"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:office_web_components:2002:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "316D6CD7-3B2B-499C-ADBE-088981DFD306"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:project:2000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F09162C-01F0-4056-94D3-995713F92AE9"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:project:2002:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2AE2D3E0-49E4-410E-B63A-753BDE8995BB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}