CVE-2002-0861
Estado: ModificadaAlta (7.5)—
Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 16%
- Percentil entre todas las CVEs puntuadas: 97
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- NVD-CWE-Other
Referencias
- http://marc.info/?l=bugtraq&m=101829726516346&w=2
- http://www.iss.net/security_center/static/8779.php
- http://www.securityfocus.com/bid/4457
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-044
- http://marc.info/?l=bugtraq&m=101829726516346&w=2
- http://www.iss.net/security_center/static/8779.php
- http://www.securityfocus.com/bid/4457
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-044
JSON original (NVD)
Mostrar
{
"id": "CVE-2002-0861",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2002-09-24T04:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=101829726516346&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/8779.php",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/4457",
"source": "cve@mitre.org"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-044",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=101829726516346&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iss.net/security_center/static/8779.php",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/4457",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-044",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the \"Allow paste operations via script\" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object."
},
{
"lang": "es",
"value": "Microsoft Office Web Components (OWC) 2000 y 2002 permite a atacantes remotos sortear la configuración de \"Permitir pegar mediante script\", incluso cuando está desactivada, mediante:\r\nel método Copy del objeto Cell (celda)\r\nel método Paste (pegar) del objeto Range (rango)"
}
],
"lastModified": "2026-06-16T21:58:17.023",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:office_web_components:2000:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A431CA59-8BD3-48CB-82BC-8FDCFE7440FA"
},
{
"criteria": "cpe:2.3:a:microsoft:office_web_components:2002:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "316D6CD7-3B2B-499C-ADBE-088981DFD306"
},
{
"criteria": "cpe:2.3:a:microsoft:project:2000:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3F09162C-01F0-4056-94D3-995713F92AE9"
},
{
"criteria": "cpe:2.3:a:microsoft:project:2002:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2AE2D3E0-49E4-410E-B63A-753BDE8995BB"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}