File Detection Vulnerability in Office Web Components by Microsoft
CVE-2002-1340

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
18 December 2002

Summary

The 'ConnectionFile' property within the DataSourceControl component of Office Web Components (OWC) 10 is vulnerable, enabling remote attackers to infer the existence of local files. This is achieved by provoking an exception when a requested file is not accessible, which can be exploited to gather information about the file structure on a user's system.

References

EPSS Score

14% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.