CVE-2002-1056 describes a vulnerability in Microsoft Outlook 2000 and 2002 when configured to use Microsoft Word as the email editor. This flaw allows remote attackers to execute arbitrary scripts by sending an email containing malicious HTML or Rich Text Format (RTF) content, which triggers upon the user forwarding or replying to the message. With a CVSS score of 7.5, this vulnerability is considered highly severe due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. Despite its age, there is no evidence of active exploitation, nor are there publicly available exploits in Metasploit, Nuclei, or ExploitDB, though it has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2000:*:*:*:*:*:*:* | ||
2002CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2002:*:*:*:*:*:*:* | ||
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:word:2000:*:*:*:*:*:*:* | ||
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:word:2000:sr1:*:*:*:*:*:* | ||
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:word:2000:sr1a:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.