← Vulnerability feed

Vulnerability record · CVE-2002-1143 · published 11 April 2003

CVE-2002-1143: Microsoft Word and Excel field codes leak local data to remote attackers

Microsoft · Excel

Microsoft Word and Excel process certain field codes, such as INCLUDETEXT and INCLUDEPICTURE, that pull in external content when a document is opened or updated. A crafted document can cause the victim's application to insert sensitive local information into the file, which is then returned to the attacker when the document is sent back. This is an information disclosure flaw in widely deployed office software.

5.0 CVSS 2.0 Medium EPSS 54% · top 1.0%
5.0CVSS 2.0 base score
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
20References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityCVSS 2.0 rates this 5.0 (medium) with only partial confidentiality impact, but high EPSS and a public exploit reference raise the practical risk for document-heavy environments.

What it is

Microsoft Word and Excel process certain field codes, such as INCLUDETEXT and INCLUDEPICTURE, that pull in external content when a document is opened or updated. A crafted document can cause the victim's application to insert sensitive local information into the file, which is then returned to the attacker when the document is sent back. This is an information disclosure flaw in widely deployed office software.

Impact

An attacker gains read access to sensitive information from the victim's system that is embedded into the returned document; there is no integrity or availability impact. The exposure is limited to partial confidentiality loss rather than full system compromise.

Attack surface

Reached remotely over the network with no authentication required, per the CVSS vector AV:N/AC:L/Au:N. Exploitation depends on the victim opening or updating a malicious document and returning it, so user interaction is effectively required even though the vector does not encode it.

Exploitation

CISA KEV does not list this CVE, but EPSS is high at roughly 0.536 (99th percentile), and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware group is documented as using it.

What to do

  • Apply the vendor patch referenced in Microsoft Security Bulletin MS02-059 and the Microsoft Word security guidance page.
  • Disable or restrict automatic update of external links and field codes in Word and Excel, and block INCLUDETEXT and INCLUDEPICTURE fields in untrusted documents.
  • Treat documents from external or untrusted sources as hostile; open them in a sandbox or Protected View and avoid returning edited copies to the sender.
  • Use document inspection or policy controls to strip field codes and external references before documents leave the environment.

Detection

  • Monitor for Word or Excel documents containing INCLUDETEXT or INCLUDEPICTURE field codes, especially in inbound mail attachments.
  • Alert on outbound documents or email containing embedded local file paths or content pulled from the host.
  • Review endpoint logs for Office processes making unexpected external file or network requests during document open or field update.
  • Hunt for repeated document round-trips to external recipients that coincide with field-code insertion activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://marc.info/?l=bugtraq&m=103040003014999&w=2 Mailing ListThird Party Advisory
http://marc.info/?l=bugtraq&m=103252858816401&w=2 Mailing ListThird Party Advisory
http://www.iss.net/security_center/static/10008.php Broken Link
http://www.iss.net/security_center/static/10155.php Broken Link
http://www.kb.cert.org/vuls/id/899713 Third Party AdvisoryUS Government Resource
http://www.microsoft.com/technet/treeview/default.asp?url=/Technet/security/topics/secword.asp PatchVendor Advisory
http://www.securityfocus.com/bid/5586 ExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
http://www.securityfocus.com/bid/5764 Third Party AdvisoryVDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-059
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A202 Third Party Advisory
http://marc.info/?l=bugtraq&m=103040003014999&w=2 Mailing ListThird Party Advisory
http://marc.info/?l=bugtraq&m=103252858816401&w=2 Mailing ListThird Party Advisory
http://www.iss.net/security_center/static/10008.php Broken Link
http://www.iss.net/security_center/static/10155.php Broken Link
http://www.kb.cert.org/vuls/id/899713 Third Party AdvisoryUS Government Resource
http://www.microsoft.com/technet/treeview/default.asp?url=/Technet/security/topics/secword.asp PatchVendor Advisory
http://www.securityfocus.com/bid/5586 ExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
http://www.securityfocus.com/bid/5764 Third Party AdvisoryVDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-059
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A202 Third Party Advisory

Track CVE-2002-1143 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2009-0238Microsoft Excel invalid object access allows remote code executionMicrosoft Excel and related viewers (Excel 2000 through 2007, Excel Viewer, Office Compatibility Pack, and Office for Mac 2004/2008) fail to handle a…KEVEPSS 43%analysed8.8CVE-2007-0671Microsoft Excel remote code execution via malformed fileCVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows re…KEVEPSS 43%analysed7.8CVE-2021-42292Microsoft Excel security feature bypass via crafted fileCVE-2021-42292 is a security feature bypass in Microsoft Excel and related Office products. The record gives only a one-line description, so the exac…KEVEPSS 43%analysed7.8CVE-2018-0802Microsoft Office Equation Editor Memory Corruption RCEEquation Editor in Microsoft Office 2007, 2010, 2013, and 2016 mishandles objects in memory, causing an out-of-bounds write (CWE-787) that can lead t…KEVEPSS 93%analysed7.8CVE-2017-11826Microsoft Office memory corruption allows remote code executionMicrosoft Office, Word, SharePoint, Office Web Apps and related products fail to properly handle objects in memory, a buffer overflow (CWE-119) that …KEVEPSS 81%analysed

Source: NIST National Vulnerability Database (record CVE-2002-1143), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.